<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" nvd_xml_version="2.0" pub_date="2009-11-07T04:10:00" xsi:schemaLocation="http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
    <entry id="CVE-1999-0095">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:5.58" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:eric_allman:sendmail:5.58</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0095</vuln:cve-id>
        <vuln:published-datetime>1988-10-01T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:41.790-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/1">1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/195">195</vuln:reference>
        </vuln:references>
        <vuln:summary>The debug command in Sendmail is enabled, allowing attackers to execute commands as root.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0082">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ftp:ftp" />
                <cpe-lang:fact-ref name="cpe:/a:ftpcd:ftpcd" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ftp:ftp</vuln:product>
            <vuln:product>cpe:/a:ftpcd:ftpcd</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0082</vuln:cve-id>
        <vuln:published-datetime>1988-11-11T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:40.853-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FarmerVenema</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html">Improving the Security of Your Site by Breaking Into it</vuln:reference>
        </vuln:references>
        <vuln:summary>CWD ~root command in ftpd allows root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1471">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:bsd:bsd:4.2" />
                <cpe-lang:fact-ref name="cpe:/o:bsd:bsd:4.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:bsd:bsd:4.3</vuln:product>
            <vuln:product>cpe:/o:bsd:bsd:4.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1471</vuln:cve-id>
        <vuln:published-datetime>1989-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:36.257-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1989-01.html">CA-1989-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/4">4</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/7152.php">bsd-passwd-bo(7152)</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in passwd in BSD based operating systems 4.3 and earlier allows local users to gain root privileges by specifying a long shell or GECOS field.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1122">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.0.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.0.3</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1122</vuln:cve-id>
        <vuln:published-datetime>1989-07-26T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:46.417-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1989-02.html">CA-1989-02</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/6695">sun-restore-gain-privileges(6695)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/3">3</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/ciac-08.shtml">CIAC-08</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in restore in SunOS 4.0.3 and earlier allows local users to gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1467">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.2" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.3c" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.0.3c</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.0.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.0.2</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.0.3</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1467</vuln:cve-id>
        <vuln:published-datetime>1989-10-26T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:35.630-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1989-07.html">CA-1989-07</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/3165.php">sun-rcp(3165)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/5">5</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1506">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:3.5" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.2" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.3c" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.0.3c</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.0.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.0.2</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.0.3</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.0</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:3.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1506</vuln:cve-id>
        <vuln:published-datetime>1990-01-29T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:41.257-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-90.01.sun.sendmail.vulnerability">CA-1990-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6">6</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in SMI Sendmail 4.0 and earlier, on SunOS up to 4.0.3, allows remote attackers to access user bin.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0084">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sun:nfs" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sun:nfs</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0084</vuln:cve-id>
        <vuln:published-datetime>1990-05-01T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:16:25.283-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/78">nfs-mknod(78)</vuln:reference>
        </vuln:references>
        <vuln:summary>Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.</vuln:summary>
    </entry>
    <entry id="CVE-2000-0388">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.1" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.2" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.3" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:freebsd:freebsd:3.0</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:3.4</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:3.3</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:3.2</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:3.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2000-0388</vuln:cve-id>
        <vuln:published-datetime>1990-05-09T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:04:33.930-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/1185">1185</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FREEBSD</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00%3A17.libmytinfo.asc">FreeBSD-SA-00:17</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in FreeBSD libmytinfo library allows local users to execute commands via a long TERMCAP environmental variable.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0209">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:3.5" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.2" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.0.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.0.2</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.0.3</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.0</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:3.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0209</vuln:cve-id>
        <vuln:published-datetime>1990-08-14T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:01.117-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/8">8</vuln:reference>
        </vuln:references>
        <vuln:summary>The SunView (SunTools) selection_svc facility allows remote users to read files.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1198">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:next:next:2.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:next:next:2.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1198</vuln:cve-id>
        <vuln:published-datetime>1990-10-03T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:57.260-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1990-06.html">CA-1990-06</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/b-01.shtml">B-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/11">11</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/7141.php">nextstep-builddisk-root-access(7141)</vuln:reference>
        </vuln:references>
        <vuln:summary>BuildDisk program on NeXT systems before 2.0 does not prompt users for the root password, which allows local users to gain root privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1391">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:next:next:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:next:next:1.0a" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:next:next:1.0a</vuln:product>
            <vuln:product>cpe:/a:next:next:1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1391</vuln:cve-id>
        <vuln:published-datetime>1990-10-03T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:24.600-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1990-06.html">CA-1990-06</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/b-01.shtml">B-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/10">10</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/7143.php">nextstep-npd-root-access(7143)</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in NeXT 1.0a and 1.0 with publicly accessible printers allows local users to gain privileges via a combination of the npd program and weak directory permissions.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1392">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:next:nex:1.0a" />
                <cpe-lang:fact-ref name="cpe:/a:next:next:1.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:next:next:1.0</vuln:product>
            <vuln:product>cpe:/a:next:nex:1.0a</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1392</vuln:cve-id>
        <vuln:published-datetime>1990-10-03T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:24.740-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1990-06.html">CA-1990-06</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9">9</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/b-01.shtml">B-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/7144.php">nextstep-restore09-root-access(7144)</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in restore0.9 installation script in NeXT 1.0a and 1.0 allows local users to gain root privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1057">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:digital:vms:5.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:digital:vms:5.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1057</vuln:cve-id>
        <vuln:published-datetime>1990-10-25T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:37.230-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1990-07.html">CA-1990-07</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/b-04.shtml">B-04</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12">12</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/7137.php">vms-analyze-processdump-privileges(7137)</vuln:reference>
        </vuln:references>
        <vuln:summary>VMS 4.0 through 5.3 allows local users to gain privileges via the ANALYZE/PROCESS_DUMP dcl command.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1554">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.3" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.3.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sgi:irix:3.3.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:3.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1554</vuln:cve-id>
        <vuln:published-datetime>1990-10-31T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:48.163-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1990-08.html">CA-1990-08</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/13">13</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/3164.php">sgi-irix-reset(3164)</vuln:reference>
        </vuln:references>
        <vuln:summary>/usr/sbin/Mail on SGI IRIX 3.3 and 3.3.1 does not properly set the group ID to the group ID of the user who started Mail, which allows local users to read the mail of other users.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1197">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1197</vuln:cve-id>
        <vuln:published-datetime>1990-12-20T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:57.117-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1990-12.html">CA-1990-12</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/14">14</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/7140.php">sunos-tioccons-console-redirection(7140)</vuln:reference>
        </vuln:references>
        <vuln:summary>TIOCCONS in SunOS 4.1.1 does not properly check the permissions of a user who tries to redirect console output and input, which could allow a local user to gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1115">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:apollo_domain_os:sr10.2" />
                <cpe-lang:fact-ref name="cpe:/o:hp:apollo_domain_os:sr10.3:beta" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:apollo_domain_os:sr10.2</vuln:product>
            <vuln:product>cpe:/o:hp:apollo_domain_os:sr10.3:beta</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1115</vuln:cve-id>
        <vuln:published-datetime>1990-12-31T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:45.430-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1990-04.html">CA-1990-04</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/7">7</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/6721.php">apollo-suidexec-unauthorized-access(6721)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/a-30.shtml">A-30</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in the /etc/suid_exec program in HP Apollo Domain/OS sr10.2 and sr10.3 beta, related to the Korn Shell (ksh).</vuln:summary>
    </entry>
    <entry id="CVE-1999-1258">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1258</vuln:cve-id>
        <vuln:published-datetime>1991-01-15T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:05.883-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/1782.php">sun-pwdauthd(1782)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUN</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/102">00102</vuln:reference>
        </vuln:references>
        <vuln:summary>rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1438">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.0.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1438</vuln:cve-id>
        <vuln:published-datetime>1991-02-22T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:31.490-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-91.01a.SunOS.mail.vulnerability">CA-1991-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUN</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/105">00105</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/15">15</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via certain command line arguments.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1211">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1211</vuln:cve-id>
        <vuln:published-datetime>1991-03-27T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:59.167-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1991-02.html">CA-1991-02</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/574.php">sun-intelnetd(574)</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in in.telnetd in SunOS 4.1.1 and earlier allows local users to gain root privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1212">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.3c" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.0.3c</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.0.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1212</vuln:cve-id>
        <vuln:published-datetime>1991-03-27T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:59.307-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1991-02.html">CA-1991-02</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/574.php">sun-intelnetd(574)</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in in.rlogind in SunOS 4.0.3 and 4.0.3c allows local users to gain root privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1194">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:digital:ultrix:4.0" />
                <cpe-lang:fact-ref name="cpe:/o:digital:ultrix:4.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:digital:ultrix:4.1</vuln:product>
            <vuln:product>cpe:/o:digital:ultrix:4.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1194</vuln:cve-id>
        <vuln:published-datetime>1991-05-01T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:56.713-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1991-05.html">CA-1991-05</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/577.php">dec-chroot(577)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/17">17</vuln:reference>
        </vuln:references>
        <vuln:summary>chroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1193">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:next:next:2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:next:next:2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1193</vuln:cve-id>
        <vuln:published-datetime>1991-05-14T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:56.570-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1991-06.html">CA-1991-06</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/581.php">next-me(581)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/20">20</vuln:reference>
        </vuln:references>
        <vuln:summary>The "me" user in NeXT NeXTstep 2.1 and earlier has wheel group privileges, which could allow the me user to use the su command to become root.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1123">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.0.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1123</vuln:cve-id>
        <vuln:published-datetime>1991-05-20T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:46.573-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1991-07.html">CA-1991-07</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/582.php">sun-sourcetapes(582)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUN</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/107&amp;type=0&amp;nav=sec.sba">00107</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/22">22</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/21">21</vuln:reference>
        </vuln:references>
        <vuln:summary>The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1034">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:att:svr4:4.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:att:svr4:4.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1034</vuln:cve-id>
        <vuln:published-datetime>1991-05-23T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:34.057-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1991-08.html">CA-1991-08</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/23">23</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/583.php">sysv-login(583)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/b-28.shtml">B-28</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in login in AT&amp;T System V Release 4 allows local users to gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1415">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:digital:ultrix:4.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:digital:ultrix:4.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1415</vuln:cve-id>
        <vuln:published-datetime>1991-08-23T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:28.163-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-91.13.Ultrix.mail.vulnerability">CA-91.13</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27">27</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in /usr/bin/mail in DEC ULTRIX before 4.2 allows local users to gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1090">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ncsa:telnet" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ncsa:telnet</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1090</vuln:cve-id>
        <vuln:published-datetime>1991-09-10T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:41.963-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1991-15.html">CA-1991-15</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/1844.php">ftp-ncsa(1844)</vuln:reference>
        </vuln:references>
        <vuln:summary>The default configuration of NCSA Telnet package for Macintosh and PC enables FTP, even though it does not include an "ftp=yes" line, which allows remote attackers to read and modify arbitrary files.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0498">
        <vuln:cve-id>CVE-1999-0498</vuln:cve-id>
        <vuln:published-datetime>1991-09-27T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:39.197-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>TFTP is not running in a restricted directory, allowing a remote attacker to access sensitive information such as password files.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1468">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:next:next:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:next:next:2.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.3" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.3.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.3.2" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.3.3" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:cray:unicos:6.0" />
                <cpe-lang:fact-ref name="cpe:/o:cray:unicos:6.0e" />
                <cpe-lang:fact-ref name="cpe:/o:cray:unicos:6.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.3c" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1psr_a" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.0.3c</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:4.0</vuln:product>
            <vuln:product>cpe:/o:cray:unicos:6.0</vuln:product>
            <vuln:product>cpe:/o:cray:unicos:6.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.0.3</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1psr_a</vuln:product>
            <vuln:product>cpe:/a:next:next:2.0</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:3.3.2</vuln:product>
            <vuln:product>cpe:/a:next:next:2.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:3.3.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:3.3</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:3.3.3</vuln:product>
            <vuln:product>cpe:/o:cray:unicos:6.0e</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1468</vuln:cve-id>
        <vuln:published-datetime>1991-10-22T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:01:59.960-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>6.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-91.20.rdist.vulnerability">CA-91.20</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/31">31</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-01.html">http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-01.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/8106">8106</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/7160.php">rdist-popen-gain-privileges(7160)</vuln:reference>
        </vuln:references>
        <vuln:summary>rdist in various UNIX systems uses popen to execute sendmail, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0167">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0167</vuln:cve-id>
        <vuln:published-datetime>1991-12-06T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:53.697-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:summary>In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1493">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:apollo_domain_os:sr10.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:apollo_domain_os:sr10.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1493</vuln:cve-id>
        <vuln:published-datetime>1991-12-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:39.413-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1991-23.html">CA-1991-23</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/7158.php">apollo-crp-root-access(7158)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/34">34</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in crp in Hewlett Packard Apollo Domain OS SR10 through SR10.3 allows remote attackers to gain root privileges via insecure system calls, (1) pad_$dm_cmd and (2) pad_$def_pfk().</vuln:summary>
    </entry>
    <entry id="CVE-1999-1032">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:digital:ultrix:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:digital:ultrix:4.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:digital:ultrix:4.1</vuln:product>
            <vuln:product>cpe:/o:digital:ultrix:4.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1032</vuln:cve-id>
        <vuln:published-datetime>1991-12-31T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:33.777-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1991-11.html">CA-1991-11</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/26">26</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/584.php">ultrix-telnet(584)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/b-36.shtml">B-36</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in LAT/Telnet Gateway (lattelnet) on Ultrix 4.1 and 4.2 allows attackers to gain root privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1059">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:att:svr4:4.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:att:svr4:4.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1059</vuln:cve-id>
        <vuln:published-datetime>1992-02-25T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:37.527-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1992-04.html">CA-1992-04</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/36">36</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/3159.php">att-rexecd(3159)</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in rexec daemon (rexecd) in AT&amp;T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0627">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.1" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:ibm:aix:3.1</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0627</vuln:cve-id>
        <vuln:published-datetime>1992-03-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:35:08.743-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>0.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>The rexd service is running, which uses weak authentication that can allow an attacker to execute commands.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1121">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1121</vuln:cve-id>
        <vuln:published-datetime>1992-03-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:46.277-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1992-06.html">CA-1992-06</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/554.php">ibm-uucp(554)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/38">38</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/891">891</vuln:reference>
        </vuln:references>
        <vuln:summary>The default configuration for UUCP in AIX before 3.2 allows local users to gain root privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0117">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.1" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:ibm:aix:3.1</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0117</vuln:cve-id>
        <vuln:published-datetime>1992-03-31T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:47.057-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>AIX passwd allows local users to gain root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1119">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:::32-bit" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:ibm:aix:::32-bit</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1119</vuln:cve-id>
        <vuln:published-datetime>1992-04-27T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:45.993-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1992-09.html">CA-1992-09</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/3154.php">aix-anon-ftp(3154)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/41">41</vuln:reference>
        </vuln:references>
        <vuln:summary>FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1142">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.1.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1142</vuln:cve-id>
        <vuln:published-datetime>1992-05-27T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:49.323-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1992-11.html">CA-1992-11</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/3152.php">sun-env(3152)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUN</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/116">00116</vuln:reference>
        </vuln:references>
        <vuln:summary>SunOS 4.1.2 and earlier allows local users to gain privileges via "LD_*" environmental variables to certain dynamically linked setuid or setgid programs such as (1) login, (2) su, or (3) sendmail, that change the real and effective user ids to the same user.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0168">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3c" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3c</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0168</vuln:cve-id>
        <vuln:published-datetime>1992-06-04T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:53.757-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:summary>The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place.  For example, NFS file systems could be mounted through the portmapper despite export restrictions.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0214">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.2</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0214</vuln:cve-id>
        <vuln:published-datetime>1992-07-21T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:01.507-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>Denial of service by sending forged ICMP unreachable packets.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1396">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.2</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1396</vuln:cve-id>
        <vuln:published-datetime>1992-07-21T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:25.337-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1992-15.html">CA-1992-15</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/49">49</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/7150.php">sun-integer-multiplication-access(7150)</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in integer multiplication emulation code on SPARC architectures for SunOS 4.1 through 4.1.2 allows local users to gain root access or cause a denial of service (crash).</vuln:summary>
    </entry>
    <entry id="CVE-1999-1395">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.0" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.1" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.1b" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.2" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.3" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.3.2" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.4" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.4.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:dec:dec_openvms:5.4</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.1.1</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.1.2</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.4.1</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.1</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.0</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.2.1</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.3</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.2</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.4.2</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.1b</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.0.1</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.0.2</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.3.1</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.3.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1395</vuln:cve-id>
        <vuln:published-datetime>1992-11-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T00:02:35.750-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-92.16.VMS.Monitor.vulnerability">CA-92.16</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1992-18.html">CA-1992-18</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/51">51</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/7136.php">vms-monitor-gain-privileges(7136)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59332">59332</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in Monitor utility (SYS$SHARE:SPISHR.EXE) in VMS 5.0 through 5.4-2 allows local users to gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1306">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:9.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:cisco:ios:9.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1306</vuln:cve-id>
        <vuln:published-datetime>1992-12-10T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:12.727-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1992-20.html">CA-1992-20</vuln:reference>
        </vuln:references>
        <vuln:summary>Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache is enabled and the "established" keyword is set, which could allow attackers to bypass filters.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1466">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:8.2" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:8.3" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:9.0" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:9.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:cisco:ios:9.1</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:8.2</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:9.0</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:8.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1466</vuln:cve-id>
        <vuln:published-datetime>1992-12-10T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:35.477-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1992-20.html">CA-1992-20</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/53">53</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in Cisco routers versions 8.2 through 9.1 allows remote attackers to bypass access control lists when extended IP access lists are used on certain interfaces, the IP route cache is enabled, and the access list uses the "established" keyword.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1021">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.2</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1021</vuln:cve-id>
        <vuln:published-datetime>1992-12-30T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:32.197-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1992-15.html">CA-1992-15</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/47">47</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUN</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/117&amp;type=0&amp;nav=sec.sba">00117</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/82.php">nfs-uid(82)</vuln:reference>
        </vuln:references>
        <vuln:summary>NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1056">
        <vuln:cve-id>CVE-1999-1056</vuln:cve-id>
        <vuln:published-datetime>1992-12-31T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:36:47.930-04:00</vuln:last-modified-datetime>
        <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1395.  Reason: This candidate is a duplicate of CVE-1999-1395.  Notes: All CVE users should reference CVE-1999-1395 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0312">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0312</vuln:cve-id>
        <vuln:published-datetime>1993-01-13T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:16.477-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>HP ypbind allows attackers with root privileges to modify NIS data.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1507">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.2" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3c" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1psr_a" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.2</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1psr_a</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3c</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1507</vuln:cve-id>
        <vuln:published-datetime>1993-02-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:41.413-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1993-03.html">CA-1993-03</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/59">59</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/521.php">sun-dir(521)</vuln:reference>
        </vuln:references>
        <vuln:summary>Sun SunOS 4.1 through 4.1.3 allows local attackers to gain root access via insecure permissions on files and directories such as crash.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1218">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:commodore:amiga_unix:2.1p2a" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:commodore:amiga_unix:2.1p2a</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1218</vuln:cve-id>
        <vuln:published-datetime>1993-02-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:00.167-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1993-04.html">CA-1993-04</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/522.php">amiga-finger(522)</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in finger in Commodore Amiga UNIX 2.1p2a and earlier allows local users to read arbitrary files.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1312">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms_axp:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms_vax:5.5.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:dec:dec_openvms_vax:5.5.2</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms_axp:1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1312</vuln:cve-id>
        <vuln:published-datetime>1993-02-24T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:13.523-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1993-05.html">CA-1993-05</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/7142.php">openvms-local-privilege-elevation(7142)</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in DEC OpenVMS VAX 5.5-2 through 5.0, and OpenVMS AXP 1.0, allows local users to gain system privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1216">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:cisco:router:8.2" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:router:8.3" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:router:9.0" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:router:9.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:router:9.17" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:cisco:router:9.17</vuln:product>
            <vuln:product>cpe:/h:cisco:router:9.0</vuln:product>
            <vuln:product>cpe:/h:cisco:router:9.1</vuln:product>
            <vuln:product>cpe:/h:cisco:router:8.2</vuln:product>
            <vuln:product>cpe:/h:cisco:router:8.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1216</vuln:cve-id>
        <vuln:published-datetime>1993-04-22T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:59.867-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1993-07.html">CA-1993-07</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/541.php">cisco-sourceroute(541)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/d-15.shtml">D-15</vuln:reference>
        </vuln:references>
        <vuln:summary>Cisco routers 9.17 and earlier allow remote attackers to bypass security restrictions via certain IP source routed packets that should normally be denied using the "no ip source-route" command.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1162">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:4.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sco:open_desktop:1.1</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop:2.0</vuln:product>
            <vuln:product>cpe:/o:sco:unix:4.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1162</vuln:cve-id>
        <vuln:published-datetime>1993-05-24T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:52.117-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>6.4</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1993-08.html">CA-1993-08</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/542.php">sco-passwd-deny(542)</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in passwd in SCO UNIX 4.0 and earlier allows attackers to cause a denial of service by preventing users from being able to log into the system.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0124">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:university_of_minnesota:gopherd" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:university_of_minnesota:gopherd</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0124</vuln:cve-id>
        <vuln:published-datetime>1993-08-09T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:48.587-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>Vulnerabilities in UMN gopher and gopher+ versions 1.12 and 2.0x allow an intruder to read any files that can be accessed by the gopher daemon.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1215">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:novell:netware:4.0" />
                <cpe-lang:fact-ref name="cpe:/o:novell:netware:4.01" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:novell:netware:4.0</vuln:product>
            <vuln:product>cpe:/o:novell:netware:4.01</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1215</vuln:cve-id>
        <vuln:published-datetime>1993-09-16T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:59.727-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1993-12.html">CA-1993-12</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/545.php">novell-login(545)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/d-21.shtml">D-21</vuln:reference>
        </vuln:references>
        <vuln:summary>LOGIN.EXE program in Novell Netware 4.0 and 4.01 temporarily writes user name and password information to disk, which could allow local users to gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1138">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:1.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop_lite:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:system_v386_3.2_operating_system" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:system_v386_3.2_operating_system_2.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:system_v386_3.2_operating_system_4.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:system_v386_3.2_operating_system_4.x" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sco:unix:system_v386_3.2_operating_system_4.x</vuln:product>
            <vuln:product>cpe:/o:sco:unix:system_v386_3.2_operating_system_2.0</vuln:product>
            <vuln:product>cpe:/o:sco:unix:system_v386_3.2_operating_system</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop_lite:3.0</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop:1.0</vuln:product>
            <vuln:product>cpe:/o:sco:unix:system_v386_3.2_operating_system_4.0</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop:2.0</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop:3.0</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:3.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1138</vuln:cve-id>
        <vuln:published-datetime>1993-09-17T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:48.727-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1993-13.html">CA-1993-13</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/546.php">sco-homedir(546)</vuln:reference>
        </vuln:references>
        <vuln:summary>SCO UNIX System V/386 Release 3.2, and other SCO products, installs the home directories (1) /tmp for the dos user, and (2) /usr/tmp for the asg user, which allows other users to gain access to those accounts since /tmp and /usr/tmp are world-writable.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1318">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1c" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.2" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3c" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:1.0</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.2</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:1.1c</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:1.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3c</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:1.0.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1318</vuln:cve-id>
        <vuln:published-datetime>1993-09-17T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:01:42.430-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNBUG</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fpatches%2F100630&amp;zone_32=112193%2A%20">1121935</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/7480.php">sun-su-path(7480)</vuln:reference>
        </vuln:references>
        <vuln:summary>/usr/5bin/su in SunOS 4.1.3 and earlier uses a search path that includes the current working directory (.), which allows local users to gain privileges via Trojan horse programs.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0145">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:eric_allman:sendmail</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0145</vuln:cve-id>
        <vuln:published-datetime>1993-09-30T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:50.680-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1993-14.html">CA-1993-14</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1990-11.html">CA-1990-11</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www2.dataguard.no/bugtraq/1995_1/0332.html">19950206 sendmail wizard thing...</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FarmerVenema</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html">Improving the Security of Your Site by Breaking Into it</vuln:reference>
        </vuln:references>
        <vuln:summary>Sendmail WIZ command enabled, allowing root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1137">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:2.2</vuln:product>
            <vuln:product>cpe:/o:sun:solaris</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.0</vuln:product>
            <vuln:product>cpe:/o:sun:sunos</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1137</vuln:cve-id>
        <vuln:published-datetime>1993-10-01T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:48.587-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/549.php">sun-audio(549)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/e-01.shtml">E-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUN</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/122&amp;type=0&amp;nav=sec.sba">00122</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/6436">6436</vuln:reference>
        </vuln:references>
        <vuln:summary>The permissions for the /dev/audio device on Solaris 2.2 and earlier, and SunOS 4.1.x, allow any local user to read from the device, which could be used by an attacker to monitor conversations happening near a machine that has a microphone.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0334">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:2.0</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:::x86</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0334</vuln:cve-id>
        <vuln:published-datetime>1993-12-16T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:18.117-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to obtain root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0181">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:rpc.walld:rpc.walld" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:rpc.walld:rpc.walld</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0181</vuln:cve-id>
        <vuln:published-datetime>1994-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:54.790-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>The wall daemon can be used for denial of service, social engineering attacks, or to execute remote commands.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1242">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.00" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.01" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:9.00</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9.01</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1242</vuln:cve-id>
        <vuln:published-datetime>1994-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:03.603-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/2162.php">hp-subnet-config(2162)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://packetstormsecurity.org/advisories/hpalert/003">HPSBUX9402-003</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in subnetconfig in HP-UX 9.01 and 9.0 allows local users to gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0211">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.2" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3c" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.2</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.0</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3c</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0211</vuln:cve-id>
        <vuln:published-datetime>1994-02-14T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:01.257-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/24">24</vuln:reference>
        </vuln:references>
        <vuln:summary>Extra long export lists over 256 characters in some mount daemons allows NFS directories to be mounted by anyone.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0338">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.4" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:ibm:aix:3.2.5</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0338</vuln:cve-id>
        <vuln:published-datetime>1994-02-24T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:18.383-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>AIX Licensed Program Product performance tools allow local users to gain root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0120">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1.1a" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:1.1.1a</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0120</vuln:cve-id>
        <vuln:published-datetime>1994-03-21T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:48.320-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUN</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/126">00126</vuln:reference>
        </vuln:references>
        <vuln:summary>Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1135">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1135</vuln:cve-id>
        <vuln:published-datetime>1994-04-20T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:01:10.337-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/2284.php">hp-vue(2284)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://packetstorm.securify.com/advisories/hpalert/027">HPSBUX9504-027</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in VUE 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4994 and PHSS_5438.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1146">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:8" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:8</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1146</vuln:cve-id>
        <vuln:published-datetime>1994-05-04T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:49.883-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/2060.php">hp-glanceplus-gpm(2060)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/advisories/1555">HPSBUX9405-011</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in Glance and gpm programs in GlancePlus for HP-UX 9.x and earlier allows local users to access arbitrary files and gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1388">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1388</vuln:cve-id>
        <vuln:published-datetime>1994-05-13T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:24.197-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>6.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www2.dataguard.no/bugtraq/1994_2/0207.html">19940514 [8lgm]-Advisory-7.UNIX.passwd.11-May-1994.NEWFIX</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www2.dataguard.no/bugtraq/1994_2/0197.html">19940513 [8lgm]-Advisory-7.UNIX.passwd.11-May-1994</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.dataguard.no/bugtraq/1994_4/0755.html">19941218 Sun Patch Id #102060-01</vuln:reference>
        </vuln:references>
        <vuln:summary>passwd in SunOS 4.1.x allows local users to overwrite arbitrary files via a symlink attack and the -F command line argument.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1134">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1134</vuln:cve-id>
        <vuln:published-datetime>1994-05-18T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:01:10.243-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/e-23.shtml">E-23</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/2284.php">hp-vue(2284)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://packetstorm.securify.com/advisories/hpalert/008">HPSBUX9404-008</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in Vue 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4038, PHSS_4055, and PHSS_4066.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0113">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.1" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.4" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:ibm:aix:3.1</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2.5</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0113</vuln:cve-id>
        <vuln:published-datetime>1994-05-23T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:46.773-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/458">458</vuln:reference>
        </vuln:references>
        <vuln:summary>Some implementations of rlogin allow root access if given a -froot parameter.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0423">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0423</vuln:cve-id>
        <vuln:published-datetime>1994-06-01T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:31.210-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-093">HPSBUX9903-093</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in hpterm on HP-UX 10.20 allows local users to gain additional privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0337">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:1.2.1" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:1.3" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:2.2.1" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.1" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:ibm:aix:3.1</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:2.2.1</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:1.3</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:1.2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0337</vuln:cve-id>
        <vuln:published-datetime>1994-06-03T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:18.320-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:summary>AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0207">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:great_circle_associates:majordomo:1.90" />
                <cpe-lang:fact-ref name="cpe:/a:great_circle_associates:majordomo:1.91" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:great_circle_associates:majordomo:1.91</vuln:product>
            <vuln:product>cpe:/a:great_circle_associates:majordomo:1.90</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0207</vuln:cve-id>
        <vuln:published-datetime>1994-06-09T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:00.977-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:summary>Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1239">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1239</vuln:cve-id>
        <vuln:published-datetime>1994-07-13T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:03.180-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/2261.php">hp-xauthority(2261)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/advisories/1559">HPSBUX9407-015</vuln:reference>
        </vuln:references>
        <vuln:summary>HP-UX 9.x does not properly enable the Xauthority mechanism in certain conditions, which could allow local users to access the X display even when they have not explicitly been authorized to do so.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1552">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.1" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.4" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:ibm:aix:3.1</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2.5</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1552</vuln:cve-id>
        <vuln:published-datetime>1994-07-20T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:02:10.163-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/358">358</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.insecure.org/lists/bugtraq/1994/Jul/0038.html">19940720 xnews and XDM</vuln:reference>
        </vuln:references>
        <vuln:summary>dpsexec (DPS Server) when running under XDM in IBM AIX 3.2.5 and earlier does not properly check privileges, which allows local users to overwrite arbitrary files and gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1494">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1494</vuln:cve-id>
        <vuln:published-datetime>1994-08-09T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:39.553-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/2112.php">sgi-colorview(2112)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.tryc.on.ca/archives/bugtraq/1995_1/0614.html">19950307 sigh. another Irix 5.2 hole.</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/336">336</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/19950209-01-P">19950209-00-P</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/675">19940809 Re: IRIX 5.2 Security Advisory</vuln:reference>
        </vuln:references>
        <vuln:summary>colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argument.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1219">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1219</vuln:cve-id>
        <vuln:published-datetime>1994-08-11T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:00.307-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1994-13.html">CA-1994-13</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/511.php">sgi-prn-mgr(511)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/468">468</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/e-33.shtml">E-33</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in sgihelp in the SGI help system and print manager in IRIX 5.2 and earlier allows local users to gain root privileges, possibly through the clogin command.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1238">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:8" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.05" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:9.05</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:8</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1238</vuln:cve-id>
        <vuln:published-datetime>1994-09-21T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:03.040-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/2262.php">hp-core-diag-fileset(2262)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/advisories/1531">HPSBUX9409-017</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in CORE-DIAG fileset in HP message catalog in HP-UX 9.05 and earlier allows local users to gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1022">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sgi:irix:4</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1022</vuln:cve-id>
        <vuln:published-datetime>1994-10-02T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:32.337-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>6.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/2111.php">sgi-serialports(2111)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/464">464</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/930">19941002</vuln:reference>
        </vuln:references>
        <vuln:summary>serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1310">
        <vuln:cve-id>CVE-1999-1310</vuln:cve-id>
        <vuln:published-datetime>1994-11-04T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:01:41.883-04:00</vuln:last-modified-datetime>
        <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1022.  Reason: This candidate is a duplicate of CVE-1999-1022.  Notes: All CVE users should reference CVE-1999-1022 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1302">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop_lite:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver_enterprise_system:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver_network_system:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:3.2" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:4.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:4.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sco:unix:3.2</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop_lite:3.0</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop:2.0</vuln:product>
            <vuln:product>cpe:/o:sco:openserver_network_system:3.0</vuln:product>
            <vuln:product>cpe:/o:sco:unix:4.0</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop:3.0</vuln:product>
            <vuln:product>cpe:/o:sco:unix:4.1</vuln:product>
            <vuln:product>cpe:/o:sco:openserver_enterprise_system:3.0</vuln:product>
            <vuln:product>cpe:/o:sco:unix:4.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1302</vuln:cve-id>
        <vuln:published-datetime>1994-11-30T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:01:40.913-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml">F-05</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/7586">sco-pt_chmod(7586)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/8797">8797</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://ftp.cerias.purdue.edu/pub/advisories/cert/cert_bulletins/VB-94:01.sco">VB-94:01</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in pt_chmod in SCO UNIX 4.2 and earlier allows local users to gain root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1303">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop_lite:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver_enterprise_system:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver_network_system:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:3.2" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:4.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:4.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sco:unix:3.2</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop_lite:3.0</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop:2.0</vuln:product>
            <vuln:product>cpe:/o:sco:openserver_network_system:3.0</vuln:product>
            <vuln:product>cpe:/o:sco:unix:4.0</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop:3.0</vuln:product>
            <vuln:product>cpe:/o:sco:unix:4.1</vuln:product>
            <vuln:product>cpe:/o:sco:openserver_enterprise_system:3.0</vuln:product>
            <vuln:product>cpe:/o:sco:unix:4.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1303</vuln:cve-id>
        <vuln:published-datetime>1994-11-30T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:01:41.007-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SCO</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml">94:001</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in prwarn in SCO UNIX 4.2 and earlier allows local users to gain root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1304">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop_lite:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver_enterprise_system:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver_network_system:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:3.2" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:4.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:4.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sco:unix:3.2</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop_lite:3.0</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop:2.0</vuln:product>
            <vuln:product>cpe:/o:sco:openserver_network_system:3.0</vuln:product>
            <vuln:product>cpe:/o:sco:unix:4.0</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop:3.0</vuln:product>
            <vuln:product>cpe:/o:sco:unix:4.1</vuln:product>
            <vuln:product>cpe:/o:sco:openserver_enterprise_system:3.0</vuln:product>
            <vuln:product>cpe:/o:sco:unix:4.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1304</vuln:cve-id>
        <vuln:published-datetime>1994-11-30T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:01:41.087-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SCO</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml">94:001</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in login in SCO UNIX 4.2 and earlier allows local users to gain root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1305">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop_lite:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver_enterprise_system:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver_network_system:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:3.2" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:4.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unix:4.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sco:unix:3.2</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop_lite:3.0</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop:2.0</vuln:product>
            <vuln:product>cpe:/o:sco:openserver_network_system:3.0</vuln:product>
            <vuln:product>cpe:/o:sco:unix:4.0</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop:3.0</vuln:product>
            <vuln:product>cpe:/o:sco:unix:4.1</vuln:product>
            <vuln:product>cpe:/o:sco:openserver_enterprise_system:3.0</vuln:product>
            <vuln:product>cpe:/o:sco:unix:4.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1305</vuln:cve-id>
        <vuln:published-datetime>1994-11-30T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:01:41.163-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml">F-05</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in "at" program in SCO UNIX 4.2 and earlier allows local users to gain root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1248">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:8.00" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:8.02" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:8.06" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.00" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:8.06</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9.00</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:8.02</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:8.00</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1248</vuln:cve-id>
        <vuln:published-datetime>1994-11-30T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:04.460-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/2058.php">hp-supportwatch(2058)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://packetstormsecurity.org/advisories/hpalert/019">HPSBUX9411-019</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in Support Watch (aka SupportWatch) in HP-UX 8.0 through 9.0 allows local users to gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-2000-0508">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:2.1" />
                <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:2.2" />
                <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:6.0" />
                <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:6.1" />
                <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:7.0" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux:6.0" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux:6.1" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux:6.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:7.0</vuln:product>
            <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:6.0</vuln:product>
            <vuln:product>cpe:/o:redhat:linux:6.1</vuln:product>
            <vuln:product>cpe:/o:redhat:linux:6.0</vuln:product>
            <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:6.1</vuln:product>
            <vuln:product>cpe:/o:redhat:linux:6.2</vuln:product>
            <vuln:product>cpe:/o:debian:debian_linux:2.2</vuln:product>
            <vuln:product>cpe:/o:debian:debian_linux:2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2000-0508</vuln:cve-id>
        <vuln:published-datetime>1994-12-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:21:11.393-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/1372">1372</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/bugtraq/2000-06/0073.html">20000608 Remote DOS in linux rpc.lockd</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/5050.php">linux-lockd-remote-dos</vuln:reference>
        </vuln:references>
        <vuln:summary>rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0077">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0077</vuln:cve-id>
        <vuln:published-datetime>1995-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:40.477-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/139.php">tcp-seq-predict(139)</vuln:reference>
        </vuln:references>
        <vuln:summary>Predictable TCP sequence numbers allow spoofing.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0232">
        <vuln:cve-id>CVE-1999-0232</vuln:cve-id>
        <vuln:published-datetime>1995-02-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:03.007-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>Buffer overflow in NCSA WebServer (version 1.5c) gives remote access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0235">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ncsa:ncsa_web_server:1.3" />
                <cpe-lang:fact-ref name="cpe:/a:ncsa:ncsa_web_server:1.4" />
                <cpe-lang:fact-ref name="cpe:/a:ncsa:ncsa_web_server:1.4.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ncsa:ncsa_web_server:1.4.1</vuln:product>
            <vuln:product>cpe:/a:ncsa:ncsa_web_server:1.4</vuln:product>
            <vuln:product>cpe:/a:ncsa:ncsa_web_server:1.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0235</vuln:cve-id>
        <vuln:published-datetime>1995-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:03.210-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0242">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:slackware:slackware_linux</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0242</vuln:cve-id>
        <vuln:published-datetime>1995-03-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:03.680-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1098">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:bsd:bsd" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:bsd:bsd</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1098</vuln:cve-id>
        <vuln:published-datetime>1995-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:43.087-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1995-03.html">CA-1995-03</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/f-12.shtml">F-12</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/4881">4881</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/516.php">bsd-telnet(516)</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in BSD Telnet client with encryption and Kerberos 4 authentication allows remote attackers to decrypt the session via sniffing.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1243">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1243</vuln:cve-id>
        <vuln:published-datetime>1995-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:03.743-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/2113.php">sgi-permissions(2113)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/f-16.shtml">F-16</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/19950301-01-P373">19950301-01-P373</vuln:reference>
        </vuln:references>
        <vuln:summary>SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0151">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:satan:satan:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:satan:satan:1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:satan:satan:1.1</vuln:product>
            <vuln:product>cpe:/a:satan:satan:1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0151</vuln:cve-id>
        <vuln:published-datetime>1995-04-03T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:52.570-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.6</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>The SATAN session key may be disclosed if the user points the web browser to other sites, possibly allowing root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1080">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:5.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1080</vuln:cve-id>
        <vuln:published-datetime>1995-05-10T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:40.527-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92633694100270&amp;w=2">19990510 SunOS 5.7 rmmount, no nosuid.</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93971288323395&amp;w=2">19991011</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/8350">solaris-rmmount-gain-root(8350)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/250">250</vuln:reference>
        </vuln:references>
        <vuln:summary>rmmount in SunOS 5.7 may mount file systems without the nosuid flag set, contrary to the documentation and its use in previous versions of SunOS, which could allow local users with physical access to gain root privileges by mounting a floppy or CD-ROM that contains a setuid program and running volcheck, when the file systems do not have the nosuid option specified in rmmount.conf.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0161">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:10.3%283.4%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:10.3%284.2%29" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:cisco:ios:10.3%284.2%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:10.3%283.4%29</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0161</vuln:cve-id>
        <vuln:published-datetime>1995-07-31T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:53.290-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/797">797</vuln:reference>
        </vuln:references>
        <vuln:summary>In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0066">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:john_s._roberts:anyform:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:john_s._roberts:anyform:2.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:john_s._roberts:anyform:2.0</vuln:product>
            <vuln:product>cpe:/a:john_s._roberts:anyform:1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0066</vuln:cve-id>
        <vuln:published-datetime>1995-07-31T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:39.727-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/719">719</vuln:reference>
        </vuln:references>
        <vuln:summary>AnyForm CGI remote execution.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0172">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:matt_wright:formmail" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:matt_wright:formmail</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0172</vuln:cve-id>
        <vuln:published-datetime>1995-08-02T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:54.040-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:summary>FormMail CGI program allows remote execution of commands.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0203">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.6.10" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:eric_allman:sendmail:8.6.10</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0203</vuln:cve-id>
        <vuln:published-datetime>1995-08-17T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:00.710-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1580">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:5.59" />
                <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:5.61" />
                <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:5.65" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.2" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3c" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4jl" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.2</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
            <vuln:product>cpe:/a:sendmail:sendmail:5.61</vuln:product>
            <vuln:product>cpe:/a:sendmail:sendmail:5.59</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.4jl</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3c</vuln:product>
            <vuln:product>cpe:/a:sendmail:sendmail:5.65</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1580</vuln:cve-id>
        <vuln:published-datetime>1995-08-23T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:51.897-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-95.11.sun.sendmail-oR.vul">CA-1995-11</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/3278">VU#3278</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/7829">7829</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AUSCERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.auscert.org.au/render.html?it=1853&amp;cid=1978">AA-95.09</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-21.html">http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-21.html</vuln:reference>
        </vuln:references>
        <vuln:summary>SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable and passing crafted values to the -oR option.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0164">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4::x86" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:5.3</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.4</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.4::x86</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0164</vuln:cve-id>
        <vuln:published-datetime>1995-08-29T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:53.493-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>6.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/8346">8346</vuln:reference>
        </vuln:references>
        <vuln:summary>A race condition in the Solaris ps command allows an attacker to overwrite critical files.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0155">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:aladdin_enterprises:ghostscript:2.6" />
                <cpe-lang:fact-ref name="cpe:/a:aladdin_enterprises:ghostscript:3.22" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:aladdin_enterprises:ghostscript:3.22</vuln:product>
            <vuln:product>cpe:/a:aladdin_enterprises:ghostscript:2.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0155</vuln:cve-id>
        <vuln:published-datetime>1995-08-31T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:52.867-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:summary>The ghostscript command with the -dSAFER option allows remote attackers to execute commands.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0245">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0245</vuln:cve-id>
        <vuln:published-datetime>1995-09-07T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:03.883-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:summary>Some configurations of NIS+ in Linux allowed attackers to log in as the user "+".</vuln:summary>
    </entry>
    <entry id="CVE-1999-0218">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:livingston_portmaster:portmaster" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:livingston_portmaster:portmaster</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0218</vuln:cve-id>
        <vuln:published-datetime>1995-10-01T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:01.853-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>Livingston portmaster machines could be rebooted via a series of commands.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0073">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3::xfs" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1::xfs" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:digital:osf_1:1.2" />
                <cpe-lang:fact-ref name="cpe:/o:digital:osf_1:1.3" />
                <cpe-lang:fact-ref name="cpe:/o:digital:osf_1:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:digital:osf_1:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:digital:osf_1:3.2" />
                <cpe-lang:fact-ref name="cpe:/o:digital:unix:3.2g" />
                <cpe-lang:fact-ref name="cpe:/o:digital:unix:4.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sgi:irix:5.0.1</vuln:product>
            <vuln:product>cpe:/o:digital:osf_1:1.2</vuln:product>
            <vuln:product>cpe:/o:digital:unix:4.0</vuln:product>
            <vuln:product>cpe:/o:digital:osf_1:1.3</vuln:product>
            <vuln:product>cpe:/o:digital:osf_1:2.0</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0.1::xfs</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.0</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
            <vuln:product>cpe:/o:digital:osf_1:3.2</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.3::xfs</vuln:product>
            <vuln:product>cpe:/o:digital:osf_1:3.0</vuln:product>
            <vuln:product>cpe:/o:digital:unix:3.2g</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0073</vuln:cve-id>
        <vuln:published-datetime>1995-10-13T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:40.210-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0099">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:convex:convexos:10.1" />
                <cpe-lang:fact-ref name="cpe:/o:convex:convexos:10.2" />
                <cpe-lang:fact-ref name="cpe:/o:convex:convexos:11.0" />
                <cpe-lang:fact-ref name="cpe:/o:convex:convexos:11.1" />
                <cpe-lang:fact-ref name="cpe:/o:convex:spp-ux:3" />
                <cpe-lang:fact-ref name="cpe:/o:cray:unicos:8.0" />
                <cpe-lang:fact-ref name="cpe:/o:cray:unicos:8.3" />
                <cpe-lang:fact-ref name="cpe:/o:cray:unicos:9.0" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
            <vuln:product>cpe:/o:bsdi:bsd_os:2.0.1</vuln:product>
            <vuln:product>cpe:/o:cray:unicos:9.0</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
            <vuln:product>cpe:/o:bsdi:bsd_os:2.0</vuln:product>
            <vuln:product>cpe:/o:convex:convexos:10.2</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
            <vuln:product>cpe:/o:convex:convexos:10.1</vuln:product>
            <vuln:product>cpe:/o:convex:spp-ux:3</vuln:product>
            <vuln:product>cpe:/o:convex:convexos:11.1</vuln:product>
            <vuln:product>cpe:/o:convex:convexos:11.0</vuln:product>
            <vuln:product>cpe:/o:cray:unicos:8.0</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
            <vuln:product>cpe:/o:cray:unicos:8.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0099</vuln:cve-id>
        <vuln:published-datetime>1995-10-19T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:42.103-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0241">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
            <vuln:product>cpe:/o:sgi:irix</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0241</vuln:cve-id>
        <vuln:published-datetime>1995-11-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:03.617-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0080">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0080</vuln:cve-id>
        <vuln:published-datetime>1995-11-30T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:40.697-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the "site exec" command.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0123">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:3.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:slackware:slackware_linux:3.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0123</vuln:cve-id>
        <vuln:published-datetime>1995-12-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:16:30.923-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>3.7</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:summary>Race condition in Linux mailx command allows local users to read user files.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0325">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:8" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:8</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0325</vuln:cve-id>
        <vuln:published-datetime>1995-12-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:17.477-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9406-013">HPSBUX9406-013</vuln:reference>
        </vuln:references>
        <vuln:summary>vhe_u_mnt program in HP-UX allows local users to create root files through symlinks.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0316">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sam_lantinga:splitvt:1.6.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sam_lantinga:splitvt:1.6.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0316</vuln:cve-id>
        <vuln:published-datetime>1995-12-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:16.757-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>Buffer overflow in Linux splitvt command gives root access to local users.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0208">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:nec:asl_ux_4800" />
                <cpe-lang:fact-ref name="cpe:/o:nec:ews-ux_v" />
                <cpe-lang:fact-ref name="cpe:/o:nec:up-ux_v" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
            <vuln:product>cpe:/o:nec:asl_ux_4800</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:4</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.0</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:3</vuln:product>
            <vuln:product>cpe:/o:nec:ews-ux_v</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
            <vuln:product>cpe:/o:nec:up-ux_v</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0208</vuln:cve-id>
        <vuln:published-datetime>1995-12-12T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:01.057-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1186">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux:2.1" />
                <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:3.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:redhat:linux:2.1</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt</vuln:product>
            <vuln:product>cpe:/o:slackware:slackware_linux:3.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1186</vuln:cve-id>
        <vuln:published-datetime>1996-01-02T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:55.557-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418966&amp;w=2">19960102 rxvt security hole</vuln:reference>
        </vuln:references>
        <vuln:summary>rxvt, when compiled with the PRINT_PIPE option in various Linux operating systems including Linux Slackware 3.0 and RedHat 2.1, allows local users to gain root privileges by specifying a malicious program using the -print-pipe command line parameter.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1319">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1319</vuln:cve-id>
        <vuln:published-datetime>1996-01-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:01:42.493-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/19960101-01-PX">19960101-01-PX</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/7430.php">irix-object-server(7430)</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in object server program in SGI IRIX 5.2 through 6.1 allows remote attackers to gain root privileges in certain configurations.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1491">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux:2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:redhat:linux:2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1491</vuln:cve-id>
        <vuln:published-datetime>1996-02-02T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:39.130-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/354">354</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418994&amp;w=2">19960202 abuse Red Hat 2.1 security hole</vuln:reference>
        </vuln:references>
        <vuln:summary>abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0103">
        <vuln:cve-id>CVE-1999-0103</vuln:cve-id>
        <vuln:published-datetime>1996-02-08T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:45.603-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0143">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:4.0" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5" />
                <cpe-lang:fact-ref name="cpe:/a:process_software:multinet:3.4" />
                <cpe-lang:fact-ref name="cpe:/a:process_software:multinet:3.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mit:kerberos:4.0</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
            <vuln:product>cpe:/a:process_software:multinet:3.4</vuln:product>
            <vuln:product>cpe:/a:process_software:multinet:3.5</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0143</vuln:cve-id>
        <vuln:published-datetime>1996-02-21T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:49.883-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:summary>Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0233">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:1.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:internet_information_server:1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0233</vuln:cve-id>
        <vuln:published-datetime>1996-02-25T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:03.070-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MSKB</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q155056">Q155056</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MSKB</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q148188">Q148188</vuln:reference>
        </vuln:references>
        <vuln:summary>IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0142">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:netscape:navigator" />
                <cpe-lang:fact-ref name="cpe:/a:sun:java" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:netscape:navigator</vuln:product>
            <vuln:product>cpe:/a:sun:java</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0142</vuln:cve-id>
        <vuln:published-datetime>1996-03-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:49.820-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:summary>The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0067">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:ncsa:ncsa_httpd:1.5a::export" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ncsa:ncsa_httpd:1.5a::export</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.0.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0067</vuln:cve-id>
        <vuln:published-datetime>1996-03-20T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:39.807-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1996-06.html">CA-1996-06</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/629">629</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/136">136</vuln:reference>
        </vuln:references>
        <vuln:summary>phf CGI program allows remote command execution through shell metacharacters.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0141">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:netscape:navigator:2.02" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:netscape:navigator:2.02</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0141</vuln:cve-id>
        <vuln:published-datetime>1996-03-29T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:49.757-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>3.7</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUN</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/134">00134</vuln:reference>
        </vuln:references>
        <vuln:summary>Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0070">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server" />
                <cpe-lang:fact-ref name="cpe:/a:ncsa:ncsa_web_server" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:http_server</vuln:product>
            <vuln:product>cpe:/a:ncsa:ncsa_web_server</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0070</vuln:cve-id>
        <vuln:published-datetime>1996-04-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:40.007-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>test-cgi program allows an attacker to list files on the server.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1103">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:digital:osf_1:3.2c" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:digital:osf_1:3.2c</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1103</vuln:cve-id>
        <vuln:published-datetime>1996-04-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:43.777-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/vendor_bulletins/VB-96.05.dec">VB-96.05</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/g-18.shtml">G-18</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.tao.ca/fire/bos/0209.html">http://www.tao.ca/fire/bos/0209.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/7138.php">osf-dxconsole-gain-privileges(7138)</vuln:reference>
        </vuln:references>
        <vuln:summary>dxconsole in DEC OSF/1 3.2C and earlier allows local users to read arbitrary files by specifying the file with the -file parameter.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0078">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ncr:mp-ras:2.03" />
                <cpe-lang:fact-ref name="cpe:/a:ncr:mp-ras:3.0" />
                <cpe-lang:fact-ref name="cpe:/a:ncr:mp-ras:3.01" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.2:stable" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2" />
                <cpe-lang:fact-ref name="cpe:/o:nec:up-ux_v" />
                <cpe-lang:fact-ref name="cpe:/o:next:nextstep" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unixware:2.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux</vuln:product>
            <vuln:product>cpe:/o:next:nextstep</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
            <vuln:product>cpe:/a:ncr:mp-ras:2.03</vuln:product>
            <vuln:product>cpe:/o:sco:unixware:2.1</vuln:product>
            <vuln:product>cpe:/a:ncr:mp-ras:3.01</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
            <vuln:product>cpe:/o:nec:up-ux_v</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5</vuln:product>
            <vuln:product>cpe:/o:bsdi:bsd_os</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:6.2:stable</vuln:product>
            <vuln:product>cpe:/a:ncr:mp-ras:3.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0078</vuln:cve-id>
        <vuln:published-datetime>1996-04-18T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:40.557-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>1.9</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0019">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:4.11" />
                <cpe-lang:fact-ref name="cpe:/a:ncr:mp-ras:2.03" />
                <cpe-lang:fact-ref name="cpe:/a:ncr:mp-ras:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:nighthawk:cx_ux" />
                <cpe-lang:fact-ref name="cpe:/o:nighthawk:powerux" />
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:2" />
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:3" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unixware:2" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5::x86" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
            <vuln:product>cpe:/a:ncr:mp-ras:2.03</vuln:product>
            <vuln:product>cpe:/a:data_general:dg_ux:4.11</vuln:product>
            <vuln:product>cpe:/o:nighthawk:cx_ux</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.4::x86</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop:3</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop:2</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:3.0</vuln:product>
            <vuln:product>cpe:/o:sco:unixware:2</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.5::x86</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.3</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.4</vuln:product>
            <vuln:product>cpe:/o:nighthawk:powerux</vuln:product>
            <vuln:product>cpe:/a:ncr:mp-ras:3.0</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0019</vuln:cve-id>
        <vuln:published-datetime>1996-04-24T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:32.460-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUN</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/135">00135</vuln:reference>
        </vuln:references>
        <vuln:summary>Delete or create a file via rpc.statd, due to invalid information.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1314">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0.5" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1:stable" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2:current" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:freebsd:freebsd:2.0</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.2</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.2:current</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.0.5</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1:stable</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1314</vuln:cve-id>
        <vuln:published-datetime>1996-05-17T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:01:42.147-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FREEBSD</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:10.mount_union.asc">FreeBSD-SA-96:10</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/7429.php">unionfs-mount-ordering(7429)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/g-24.shtml">G-24</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in union file system in FreeBSD 2.2 and earlier, and possibly other operating systems, allows local users to cause a denial of service (system reload) via a series of certain mount_union commands.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1313">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0.5" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:freebsd:freebsd:2.0</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.2</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.0.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1313</vuln:cve-id>
        <vuln:published-datetime>1996-05-23T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:13.663-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/g-24.shtml">G-24</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FREEBSD</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:11.man.asc">FreeBSD-SA-96:11</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/7348.php">bsd-man-command-sequence(7348)</vuln:reference>
        </vuln:references>
        <vuln:summary>Manual page reader (man) in FreeBSD 2.2 and earlier allows local users to gain privileges via a sequence of commands.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0522">
        <vuln:cve-id>CVE-1999-0522</vuln:cve-id>
        <vuln:published-datetime>1996-05-28T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:58.117-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>The permissions for a system-critical NIS+ table (e.g. passwd) are inappropriate.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0509">
        <vuln:cve-id>CVE-1999-0509</vuln:cve-id>
        <vuln:published-datetime>1996-05-29T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:57.180-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1253">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sco:internet_faststart:1.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sco:internet_faststart:1.0</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1253</vuln:cve-id>
        <vuln:published-datetime>1996-06-07T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:05.163-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/vendor_bulletins/VB-96.10.sco">VB-96.10</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/1965.php">sco-kernel(1965)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SCO</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.sco.com/SSE/security_bulletins/SB.96:01a">96:001</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in a kernel error handling routine in SCO OpenServer 5.0.2 and earlier, and SCO Internet FastStart 1.0, allows local users to gain root privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1205">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1205</vuln:cve-id>
        <vuln:published-datetime>1996-06-07T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:58.320-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://packetstormsecurity.org/advisories/ibm-ers/96-08">HPSBUX9607-035</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419195&amp;w=2">19960607 HP-UX B.10.01 vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/414">hp-nettune(414)</vuln:reference>
        </vuln:references>
        <vuln:summary>nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0138">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:apple:a_ux:3.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:digital:osf_1:1.3" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0.5" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:8" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.5" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:1.2.0" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:nec:asl_ux_4800" />
                <cpe-lang:fact-ref name="cpe:/o:nec:ews-ux_v:4.2" />
                <cpe-lang:fact-ref name="cpe:/o:nec:ews-ux_v:4.2mp" />
                <cpe-lang:fact-ref name="cpe:/o:nec:up-ux_v:4.2mp" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:linux_kernel:2.0</vuln:product>
            <vuln:product>cpe:/o:apple:a_ux:3.1.1</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4</vuln:product>
            <vuln:product>cpe:/o:digital:osf_1:1.3</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
            <vuln:product>cpe:/o:nec:asl_ux_4800</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.0.5</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2.5</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.0</vuln:product>
            <vuln:product>cpe:/o:nec:up-ux_v:4.2mp</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10</vuln:product>
            <vuln:product>cpe:/o:nec:ews-ux_v:4.2mp</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:1.2.0</vuln:product>
            <vuln:product>cpe:/o:nec:ews-ux_v:4.2</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:8</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0138</vuln:cve-id>
        <vuln:published-datetime>1996-06-26T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:49.557-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0175">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:novell:web_server:1.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:novell:web_server:1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0175</vuln:cve-id>
        <vuln:published-datetime>1996-07-01T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:54.243-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0022">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3::xfs" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1::xfs" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:1.1" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0.5" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.1" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.4" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.5" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.2" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.3" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.4" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.5" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.2" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:4.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:4.1.2" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:4.1.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:4.1.3:u1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:ibm:aix:4.1.4</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.1.3</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.1.5</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.1.2</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.1.1</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.0.5</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:4.1.3:u1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.3::xfs</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.0</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:4.1.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.0.1</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:4.1.2</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.1</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:4.1.3</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0.1::xfs</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.0</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2.5</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2.4</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.2</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.1</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.0</vuln:product>
            <vuln:product>cpe:/o:bsdi:bsd_os:1.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0022</vuln:cve-id>
        <vuln:published-datetime>1996-07-03T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:34.993-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUN</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/179">00179</vuln:reference>
        </vuln:references>
        <vuln:summary>Local user gains root privileges via buffer overflow in rdist, via expstr() function.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0137">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:fred_n._van_kempen:dip:3.3.7o" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:fred_n._van_kempen:dip:3.3.7o</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0137</vuln:cve-id>
        <vuln:published-datetime>1996-07-09T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:49.477-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>The dip program on many Linux systems allows local users to gain root access via a buffer overflow.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1301">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1301</vuln:cve-id>
        <vuln:published-datetime>1996-07-16T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:11.960-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/g-31.shtml">G-31</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FREEBSD</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:17.rzsz.asc">FreeBSD-SA-96:17</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/7540.php">rzsz-command-execution(7540)</vuln:reference>
        </vuln:references>
        <vuln:summary>A design flaw in the Z-Modem protocol allows the remote sender of a file to execute arbitrary programs on the client, as implemented in rz in the rzsz module of FreeBSD before 2.1.5, and possibly other programs.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1572">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0" />
                <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.0" />
                <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.1" />
                <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:9.2" />
                <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:cs2.1" />
                <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:cs3.0" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::workstation" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:4.0" />
                <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:4.10" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::enterprise_server</vuln:product>
            <vuln:product>cpe:/o:ubuntu:ubuntu_linux:4.10</vuln:product>
            <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:cs3.0</vuln:product>
            <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:10.1</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
            <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:10.0</vuln:product>
            <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::workstation</vuln:product>
            <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:9.2</vuln:product>
            <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::advanced_server</vuln:product>
            <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:cs2.1</vuln:product>
            <vuln:product>cpe:/o:debian:debian_linux:3.0</vuln:product>
            <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:4.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1572</vuln:cve-id>
        <vuln:published-datetime>1996-07-16T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:02:13.993-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19167">cpio-o-archive-insecure-permissions(19167)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2005/0003/">2005-0003</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-080.html">RHSA-2005:080</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-073.html">RHSA-2005:073</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.freebsd.org/cgi/query-pr.cgi?pr=bin/1391">http://www.freebsd.org/cgi/query-pr.cgi?pr=bin/1391</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-664">DSA-664</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-806.html">RHSA-2005:806</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:032">MDKSA-2005:032</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2005-212.pdf">http://support.avaya.com/elmodocs2/security/ASA-2005-212.pdf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17532">17532</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17063">17063</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14357">14357</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110763404701519&amp;w=2">20050204 [USN-75-1] cpio vulnerability</vuln:reference>
        </vuln:references>
        <vuln:summary>cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0023">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:inet:inet:5.01" />
                <cpe-lang:fact-ref name="cpe:/a:inet:inet:6.01" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0.5" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2" />
                <cpe-lang:fact-ref name="cpe:/o:sco:internet_faststart:1.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.2" />
                <cpe-lang:fact-ref name="cpe:/o:sco:tcp_ip:1.2.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:tcp_ip:1.2.1" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unixware:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unixware:2.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1.1a" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1.2" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sco:tcp_ip:1.2.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
            <vuln:product>cpe:/o:sco:tcp_ip:1.2.0</vuln:product>
            <vuln:product>cpe:/o:sco:unixware:2.0</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop:2.0</vuln:product>
            <vuln:product>cpe:/o:sco:unixware:2.1</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.0.5</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop:3.0</vuln:product>
            <vuln:product>cpe:/o:sco:internet_faststart:1.0</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.0</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.2</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.3</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.4</vuln:product>
            <vuln:product>cpe:/o:bsdi:bsd_os</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:1.1.2</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.5</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
            <vuln:product>cpe:/a:inet:inet:6.01</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0.2</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:1.1.1a</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:2.0</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:1.1</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
            <vuln:product>cpe:/a:inet:inet:5.01</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0023</vuln:cve-id>
        <vuln:published-datetime>1996-07-24T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:35.070-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>Local user gains root privileges via buffer overflow in rdist, via lookup() function.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0135">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::ppc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5.1::ppc</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0135</vuln:cve-id>
        <vuln:published-datetime>1996-07-25T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:49.337-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>admintool in Solaris allows a local user to write to arbitrary files and gain root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0136">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5::x86" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:5.5::x86</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.5.1::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0136</vuln:cve-id>
        <vuln:published-datetime>1996-07-31T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:49.413-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0335">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0335</vuln:cve-id>
        <vuln:published-datetime>1996-08-01T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:18.180-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>DEPRECATED.  This entry has been deprecated.  It is a duplicate of CVE-1999-0032.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1413">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1413</vuln:cve-id>
        <vuln:published-datetime>1996-08-03T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:27.883-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/296">296</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419549&amp;w=2">19960803 Exploiting Zolaris 2.4 ??  :)</vuln:reference>
        </vuln:references>
        <vuln:summary>Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0134">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5::x86" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:5.5::x86</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.4</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.4::x86</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.5.1::x86</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0134</vuln:cve-id>
        <vuln:published-datetime>1996-08-06T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:49.273-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/8159">8159</vuln:reference>
        </vuln:references>
        <vuln:summary>vold in Solaris 2.x allows local users to gain root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0133">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:adobe:framemaker" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:adobe:framemaker</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0133</vuln:cve-id>
        <vuln:published-datetime>1996-08-14T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:49.210-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0132">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.2" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.2" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3c" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.2</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.1</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.2</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.0</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3c</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0132</vuln:cve-id>
        <vuln:published-datetime>1996-08-15T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:49.133-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1996-19.html">CA-1996-19</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/401">expreserve(401)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/11723">11723</vuln:reference>
        </vuln:references>
        <vuln:summary>Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0085">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.2:stable" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2" />
                <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:6.2:stable</vuln:product>
            <vuln:product>cpe:/o:netbsd:netbsd:2.0.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0085</vuln:cve-id>
        <vuln:published-datetime>1996-08-21T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:41.103-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/119">rwhod(119)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/118">rwhod-vuln(118)</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1187">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:3.94" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0" />
                <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:3.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
            <vuln:product>cpe:/o:slackware:slackware_linux:3.0</vuln:product>
            <vuln:product>cpe:/a:university_of_washington:pine:3.94</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1187</vuln:cve-id>
        <vuln:published-datetime>1996-08-26T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:55.697-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/416.php">pine-tmpfile(416)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419803&amp;w=2">19960826 [BUG] Vulnerability in PINE</vuln:reference>
        </vuln:references>
        <vuln:summary>Pine before version 3.94 allows local users to gain privileges via a symlink attack on a lockfile that is created when a user receives new mail.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1309">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.6.7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sendmail:sendmail:8.6.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1309</vuln:cve-id>
        <vuln:published-datetime>1996-08-30T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:13.147-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-94.12.sendmail.vulnerabilities">CA-1994-12</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.dataguard.no/bugtraq/1994_1/0048.html">19940315 Security problem in sendmail versions 8.x.x</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.dataguard.no/bugtraq/1994_1/0042.html">19940315 anyone know details?</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.dataguard.no/bugtraq/1994_1/0040.html">19940314 sendmail -d problem (OLD yet still here)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/7155.php">sendmail-debug-gain-root(7155)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.dataguard.no/bugtraq/1994_1/0078.html">19940327 sendmail exploit script - resend</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.dataguard.no/bugtraq/1994_1/0043.html">19940315 so...</vuln:reference>
        </vuln:references>
        <vuln:summary>Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0324">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0324</vuln:cve-id>
        <vuln:published-datetime>1996-09-01T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:17.413-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-053">HPSBUX9702-053</vuln:reference>
        </vuln:references>
        <vuln:summary>ppl program in HP-UX allows local users to create root files through symlinks.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1252">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sco:unixware:2.0.x" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unixware:2.1.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sco:unixware:2.1.0</vuln:product>
            <vuln:product>cpe:/o:sco:unixware:2.0.x</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1252</vuln:cve-id>
        <vuln:published-datetime>1996-09-04T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:05.023-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/vendor_bulletins/VB-96.15.sco">VB-96.15</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/1966.php">sco-system-call(1966)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SCO</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.sco.COM/SSE/security_bulletins/SB.96:02a">96:002</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in a certain system call in SCO UnixWare 2.0.x and 2.1.0 allows local users to access arbitrary files and gain root privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0131">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.6" />
                <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.7.1" />
                <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.7.2" />
                <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.7.3" />
                <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.7.4" />
                <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.7.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1" />
                <cpe-lang:fact-ref name="cpe:/o:digital:osf_1:1.3.2" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.5" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux:3.0.3" />
                <cpe-lang:fact-ref name="cpe:/o:sco:internet_faststart:1.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:eric_allman:sendmail:8.6</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
            <vuln:product>cpe:/a:eric_allman:sendmail:8.7.1</vuln:product>
            <vuln:product>cpe:/a:eric_allman:sendmail:8.7.2</vuln:product>
            <vuln:product>cpe:/o:digital:osf_1:1.3.2</vuln:product>
            <vuln:product>cpe:/a:eric_allman:sendmail:8.7.5</vuln:product>
            <vuln:product>cpe:/a:eric_allman:sendmail:8.7.3</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0.2</vuln:product>
            <vuln:product>cpe:/a:eric_allman:sendmail:8.7.4</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
            <vuln:product>cpe:/o:sco:internet_faststart:1.0</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
            <vuln:product>cpe:/o:redhat:linux:3.0.3</vuln:product>
            <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0131</vuln:cve-id>
        <vuln:published-datetime>1996-09-11T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:49.070-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/717">717</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1383">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:tcsh:tcsh:6.05" />
                <cpe-lang:fact-ref name="cpe:/a:bash:bash:1.14.7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:bash:bash:1.14.7</vuln:product>
            <vuln:product>cpe:/a:tcsh:tcsh:6.05</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1383</vuln:cve-id>
        <vuln:published-datetime>1996-09-13T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:23.447-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.dataguard.no/bugtraq/1996_3/0503.html">19960919 Vulnerability in expansion of PS1 in bash &amp; tcsh</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419868&amp;w=2">19960913 tee see shell problems</vuln:reference>
        </vuln:references>
        <vuln:summary>(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \w option in the PS1 variable.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1295">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:transarc:dce_distributed_file_system:1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:transarc:dce_distributed_file_system:1.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1295</vuln:cve-id>
        <vuln:published-datetime>1996-09-17T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:11.103-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/vendor_bulletins/VB-96.16.transarc">VB-96.16</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/vendor_bulletins/VB-96.16.transarc">VB-96.16</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/7154.php">dfs-login-groups(7154)</vuln:reference>
        </vuln:references>
        <vuln:summary>Transarc DCE Distributed File System (DFS) 1.1 for Solaris 2.4 and 2.5 does not properly initialize the grouplist for users who belong to a large number of groups, which could allow those users to gain access to resources that are protected by DFS.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0116">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.5" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:ibm:sng:2.1" />
                <cpe-lang:fact-ref name="cpe:/h:ibm:sng:2.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
            <vuln:product>cpe:/h:ibm:sng:2.1</vuln:product>
            <vuln:product>cpe:/h:ibm:sng:2.2</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2.5</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0116</vuln:cve-id>
        <vuln:published-datetime>1996-09-19T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:46.977-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUN</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/136">00136</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/19961202-01-PX">19961202-01-PX</vuln:reference>
        </vuln:references>
        <vuln:summary>Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0961">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.04" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.05" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:9.04</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9.05</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0961</vuln:cve-id>
        <vuln:published-datetime>1996-09-21T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:36:15.103-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>6.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419906&amp;w=2">19960921 Vunerability in HP sysdiag ?</vuln:reference>
        </vuln:references>
        <vuln:summary>HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0206">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8" />
                <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:eric_allman:sendmail:8.8.1</vuln:product>
            <vuln:product>cpe:/a:eric_allman:sendmail:8.8</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0206</vuln:cve-id>
        <vuln:published-datetime>1996-10-01T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:00.913-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0246">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0246</vuln:cve-id>
        <vuln:published-datetime>1996-10-01T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:03.960-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>HP Remote Watch allows a remote user to gain root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0319">
        <vuln:cve-id>CVE-1999-0319</vuln:cve-id>
        <vuln:published-datetime>1996-10-01T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:16.960-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>Buffer overflow in xmcd 2.1 allows local users to gain access through a user resource setting.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0308">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:8" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:8</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0308</vuln:cve-id>
        <vuln:published-datetime>1996-10-01T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:16.197-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9410-018">HPSBUX9410-018</vuln:reference>
        </vuln:references>
        <vuln:summary>HP-UX gwind program allows users to modify arbitrary files.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0234">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/o:yggdrasil:linux" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/o:sgi:irix" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:caldera:openlinux" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux:3.0.3" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:4.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:suse:suse_linux:4.2</vuln:product>
            <vuln:product>cpe:/o:redhat:linux:3.0.3</vuln:product>
            <vuln:product>cpe:/o:sgi:irix</vuln:product>
            <vuln:product>cpe:/o:caldera:openlinux</vuln:product>
            <vuln:product>cpe:/o:yggdrasil:linux</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0234</vuln:cve-id>
        <vuln:published-datetime>1996-10-08T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:03.147-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:summary>Bash treats any character with a value of 255 as a command separator.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0075">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:washington_university:wu-ftpd</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0075</vuln:cve-id>
        <vuln:published-datetime>1996-10-16T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:40.353-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/5742">5742</vuln:reference>
        </vuln:references>
        <vuln:summary>PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0032">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0.5" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.5" />
                <cpe-lang:fact-ref name="cpe:/o:next:nextstep:4.0" />
                <cpe-lang:fact-ref name="cpe:/o:next:nextstep:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sgi:irix:5.0.1</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.0</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.0.5</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.0</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
            <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
            <vuln:product>cpe:/o:next:nextstep:4.0</vuln:product>
            <vuln:product>cpe:/o:next:nextstep:4.1</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.5</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0032</vuln:cve-id>
        <vuln:published-datetime>1996-10-25T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:35.867-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/707">707</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/i-042.shtml">I-042</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/19980402-01-PX">19980402-01-PX</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0277">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:2.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0277</vuln:cve-id>
        <vuln:published-datetime>1996-10-28T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:10.023-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>The WorkMan program can be used to overwrite any file to get root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1384">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3::xfs" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1::xfs" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sgi:irix:5.0.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0.1::xfs</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.0</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.3::xfs</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1384</vuln:cve-id>
        <vuln:published-datetime>1996-10-30T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:23.587-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AUSCERT</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.08.SGI.systour.vul">AA-96.08</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/470">470</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420095&amp;w=2">19961030 (Another) vulnerability in new SGIs</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/19961101-01-I">19961101-01-I</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/7456.php">irix-systour(7456)</vuln:reference>
        </vuln:references>
        <vuln:summary>Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst command that is executed by the RemoveSystemTour program.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0311">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:10</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0311</vuln:cve-id>
        <vuln:published-datetime>1996-11-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:16.413-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9612-042">HPSBUX9612-042</vuln:reference>
        </vuln:references>
        <vuln:summary>fpkg2swpk in HP-UX allows local users to gain root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0336">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:10</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0336</vuln:cve-id>
        <vuln:published-datetime>1996-11-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:18.243-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>Buffer overflow in mstm in HP-UX allows local users to gain root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1161">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:10</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1161</vuln:cve-id>
        <vuln:published-datetime>1996-11-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:51.977-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.codetalker.com/advisories/vendor/hp/hpsbux9704-057.html">HPSBUX9704-057</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/h-32.shtml">H-32</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420103&amp;w=2">19961104 ppl bugs</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420102&amp;w=2">19961103 Re: Untitled</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/7438.php">hp-ppl(7438)</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0130">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:caldera:network_desktop:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.7" />
                <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8" />
                <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8.1" />
                <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.5" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.6" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:caldera:network_desktop:1.0</vuln:product>
            <vuln:product>cpe:/o:redhat:linux:4.0</vuln:product>
            <vuln:product>cpe:/a:eric_allman:sendmail:8.7</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
            <vuln:product>cpe:/a:eric_allman:sendmail:8.8.1</vuln:product>
            <vuln:product>cpe:/a:eric_allman:sendmail:8.8</vuln:product>
            <vuln:product>cpe:/a:eric_allman:sendmail:8.8.2</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
            <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.5</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0130</vuln:cve-id>
        <vuln:published-datetime>1996-11-16T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:49.007-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/716">716</vuln:reference>
        </vuln:references>
        <vuln:summary>Local users can start Sendmail in daemon mode and gain root privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1221">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:digital:unix:3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:digital:unix:3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1221</vuln:cve-id>
        <vuln:published-datetime>1996-11-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:00.587-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/399.php">dgux-chpwd(399)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420141&amp;w=2">19961117 Digital Unix v3.x (v4.x?) security vulnerability</vuln:reference>
        </vuln:references>
        <vuln:summary>dxchpwd in Digital Unix (OSF/1) 3.x allows local users to modify arbitrary files via a symlink attack on the dxchpwd.log file.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1099">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:kth:kth_kerberos:4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:kth:kth_kerberos:4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1099</vuln:cve-id>
        <vuln:published-datetime>1996-11-22T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:43.227-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/65.php">kerberos-user-grab(65)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420184&amp;w=2">19961122 L0pht Kerberos Advisory</vuln:reference>
        </vuln:references>
        <vuln:summary>Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includes the realm name and the last user.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1240">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:gracenote:cddbd" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:gracenote:cddbd</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1240</vuln:cve-id>
        <vuln:published-datetime>1996-11-26T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:03.320-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/2203.php">cddbd-bo(2203)</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in cddbd CD database server allows remote attackers to execute arbitrary commands via a long log message.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0050">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.00" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.01" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.03" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.04" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.05" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.06" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.07" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.08" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.09" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.10" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9.09</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9.07</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9.08</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9.04</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9.03</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9.06</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9.05</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9.00</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9.10</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9.01</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0050</vuln:cve-id>
        <vuln:published-datetime>1996-12-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:37.147-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>Buffer overflow in HP-UX newgrp program.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0044">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0044</vuln:cve-id>
        <vuln:published-datetime>1996-12-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:36.743-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/19970301-01-P">19970301-01-P</vuln:reference>
        </vuln:references>
        <vuln:summary>fsdump command in IRIX allows local users to obtain root access by modifying sensitive files.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0129">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8" />
                <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8.1" />
                <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8.2" />
                <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.5" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.6" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.6.1" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.16" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2" />
                <cpe-lang:fact-ref name="cpe:/o:sco:internet_faststart:1.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:internet_faststart:1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.2" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:10.16</vuln:product>
            <vuln:product>cpe:/a:eric_allman:sendmail:8.8</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
            <vuln:product>cpe:/o:sco:internet_faststart:1.0</vuln:product>
            <vuln:product>cpe:/o:sco:internet_faststart:1.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.5</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.6</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
            <vuln:product>cpe:/a:eric_allman:sendmail:8.8.1</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.6.1</vuln:product>
            <vuln:product>cpe:/a:eric_allman:sendmail:8.8.2</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
            <vuln:product>cpe:/a:eric_allman:sendmail:8.8.3</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0.2</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
            <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0129</vuln:cve-id>
        <vuln:published-datetime>1996-12-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:48.930-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:summary>Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0043">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:isc:inn:1.4sec" />
                <cpe-lang:fact-ref name="cpe:/a:isc:inn:1.4sec2" />
                <cpe-lang:fact-ref name="cpe:/a:isc:inn:1.4unoff3" />
                <cpe-lang:fact-ref name="cpe:/a:isc:inn:1.4unoff4" />
                <cpe-lang:fact-ref name="cpe:/a:isc:inn:1.5" />
                <cpe-lang:fact-ref name="cpe:/a:netscape:news_server:1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1" />
                <cpe-lang:fact-ref name="cpe:/o:caldera:openlinux:1.0" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.0" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:nec:goah_intrasv:1.1" />
                <cpe-lang:fact-ref name="cpe:/h:nec:goah_networksv:1.2" />
                <cpe-lang:fact-ref name="cpe:/h:nec:goah_networksv:2.2" />
                <cpe-lang:fact-ref name="cpe:/h:nec:goah_networksv:3.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:redhat:linux:4.1</vuln:product>
            <vuln:product>cpe:/o:redhat:linux:4.0</vuln:product>
            <vuln:product>cpe:/h:nec:goah_networksv:3.1</vuln:product>
            <vuln:product>cpe:/a:netscape:news_server:1.1</vuln:product>
            <vuln:product>cpe:/h:nec:goah_networksv:1.2</vuln:product>
            <vuln:product>cpe:/h:nec:goah_intrasv:1.1</vuln:product>
            <vuln:product>cpe:/a:isc:inn:1.4sec2</vuln:product>
            <vuln:product>cpe:/a:isc:inn:1.5</vuln:product>
            <vuln:product>cpe:/o:caldera:openlinux:1.0</vuln:product>
            <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
            <vuln:product>cpe:/a:isc:inn:1.4unoff3</vuln:product>
            <vuln:product>cpe:/a:isc:inn:1.4sec</vuln:product>
            <vuln:product>cpe:/a:isc:inn:1.4unoff4</vuln:product>
            <vuln:product>cpe:/h:nec:goah_networksv:2.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0043</vuln:cve-id>
        <vuln:published-datetime>1996-12-04T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:36.647-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1401">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3::xfs" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1::xfs" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sgi:irix:5.3::xfs</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.0.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0.1::xfs</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.0</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1401</vuln:cve-id>
        <vuln:published-datetime>1996-12-05T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:26.070-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/463">463</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/19961201-01-PX">19961201-01-PX</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/7575.php">irix-searchbook-permissions(7575)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/8563">8563</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in Desktop searchbook program in IRIX 5.0.x through 6.2 sets insecure permissions for certain user files (iconbook and searchbook).</vuln:summary>
    </entry>
    <entry id="CVE-1999-0045">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:0.8.11" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:0.8.14" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.1" />
                <cpe-lang:fact-ref name="cpe:/a:netscape:commerce_server:1.12" />
                <cpe-lang:fact-ref name="cpe:/a:netscape:communications_server:1.1" />
                <cpe-lang:fact-ref name="cpe:/a:netscape:communications_server:1.12" />
                <cpe-lang:fact-ref name="cpe:/a:netscape:enterprise_server:2.0a" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:netscape:communications_server:1.12</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.0.5</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:0.8.14</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:0.8.11</vuln:product>
            <vuln:product>cpe:/a:netscape:communications_server:1.1</vuln:product>
            <vuln:product>cpe:/a:netscape:enterprise_server:2.0a</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.0.2</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.0</vuln:product>
            <vuln:product>cpe:/a:netscape:commerce_server:1.12</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.0.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0045</vuln:cve-id>
        <vuln:published-datetime>1996-12-10T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:36.807-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>List of arbitrary files on Web host via nph-test-cgi script.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0101">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0101</vuln:cve-id>
        <vuln:published-datetime>1996-12-10T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:45.460-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/h-13.shtml">H-13</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0096">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.5" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.6" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.6.1" />
                <cpe-lang:fact-ref name="cpe:/o:sco:internet_faststart:1.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:internet_faststart:1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sco:internet_faststart:1.0</vuln:product>
            <vuln:product>cpe:/o:sco:internet_faststart:1.1</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.6.1</vuln:product>
            <vuln:product>cpe:/o:bsdi:bsd_os</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0.2</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.5</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0096</vuln:cve-id>
        <vuln:published-datetime>1996-12-10T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:41.883-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUN</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/122&amp;type=0&amp;nav=sec.sba">00122</vuln:reference>
        </vuln:references>
        <vuln:summary>Sendmail decode alias can be used to overwrite sensitive files.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0297">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:paul_vixie:vixie_cron:3.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0" />
                <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0.4" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:redhat:linux</vuln:product>
            <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
            <vuln:product>cpe:/o:netbsd:netbsd:2.0.4</vuln:product>
            <vuln:product>cpe:/a:paul_vixie:vixie_cron:3.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0297</vuln:cve-id>
        <vuln:published-datetime>1996-12-12T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:14.807-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1089">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:10</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1089</vuln:cve-id>
        <vuln:published-datetime>1996-12-13T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:41.807-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml">H-21</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://ciac.llnl.gov/ciac/bulletins/h-16.shtml">H-16</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420285&amp;w=2">19961209 the HP Bug of the Week!</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in chfn command in HP-UX 9.X through 10.20 allows local users to gain privileges via a long command line argument.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0128">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:digital:osf_1:1.3.3" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:1.3.0" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:internet_faststart:1.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:internet_faststart:1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.2" />
                <cpe-lang:fact-ref name="cpe:/o:sco:tcp_ip:1.2.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5::x86" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:ibm:sng" />
                <cpe-lang:fact-ref name="cpe:/h:ibm:sng:2.1" />
                <cpe-lang:fact-ref name="cpe:/h:ibm:sng:2.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:linux_kernel:2.0</vuln:product>
            <vuln:product>cpe:/o:sco:tcp_ip:1.2.1</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
            <vuln:product>cpe:/h:ibm:sng</vuln:product>
            <vuln:product>cpe:/o:digital:osf_1:1.3.3</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.4::x86</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0.2</vuln:product>
            <vuln:product>cpe:/h:ibm:sng:2.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.5.1::x86</vuln:product>
            <vuln:product>cpe:/h:ibm:sng:2.2</vuln:product>
            <vuln:product>cpe:/o:sco:open_desktop:3.0</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
            <vuln:product>cpe:/o:sco:internet_faststart:1.0</vuln:product>
            <vuln:product>cpe:/o:sco:internet_faststart:1.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.5::x86</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:1.3.0</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:5.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0128</vuln:cve-id>
        <vuln:published-datetime>1996-12-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:48.867-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0127">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0127</vuln:cve-id>
        <vuln:published-datetime>1996-12-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:48.807-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1385">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:1.0" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:1.1" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.5" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.6" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.6.1" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.6.1</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:1.0</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.5</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:1.1</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:2.1.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1385</vuln:cve-id>
        <vuln:published-datetime>1996-12-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:01:50.570-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FREEBSD</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:20.stack-overflow.asc">FreeBSD-SA-96:20</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/6085">6085</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/7465.php">ppp-bo(7465)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420332&amp;w=2">19961219 Exploit for ppp bug (FreeBSD 2.1.0).</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in ppp program in FreeBSD 2.1 and earlier allows local users to gain privileges via a long HOME environment variable.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1026">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1026</vuln:cve-id>
        <vuln:published-datetime>1996-12-20T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:18:32.917-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/292">292</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420343&amp;w=2">19961220 Solaris 2.5 x86 aspppd (semi-exploitable-hole)</vuln:reference>
        </vuln:references>
        <vuln:summary>aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0260">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:renaud_deraison:jj" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:renaud_deraison:jj</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0260</vuln:cve-id>
        <vuln:published-datetime>1996-12-24T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:08.867-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:summary>The jj CGI program allows command execution via shell metacharacters.</vuln:summary>
    </entry>
    <entry id="CVE-1999-1251">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1251</vuln:cve-id>
        <vuln:published-datetime>1996-12-24T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:19:04.883-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/static/2010.php">hp-audio-panic(2010)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://packetstormsecurity.org/advisories/hpalert/043">HPSBUX9612-043</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in direct audio user space code on HP-UX 10.20 and 10.10 allows local users to cause a denial of service.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0265">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:microware:os-9" />
                <cpe-lang:fact-ref name="cpe:/o:novell:netware:3.12" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:novell:netware:3.12</vuln:product>
            <vuln:product>cpe:/o:microware:os-9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0265</vuln:cve-id>
        <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:09.210-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MSKB</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q154174">Q154174</vuln:reference>
        </vuln:references>
        <vuln:summary>ICMP redirect messages may crash or lock up a host.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0274">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0274</vuln:cve-id>
        <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:09.820-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0236">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server" />
                <cpe-lang:fact-ref name="cpe:/a:ncsa:servers" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:http_server</vuln:product>
            <vuln:product>cpe:/a:ncsa:servers</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0236</vuln:cve-id>
        <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:03.273-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0217">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.3c" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.2" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3a1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1psr_a" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.2</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.0.3c</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1psr_a</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1.3a1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.1</vuln:product>
            <vuln:product>cpe:/o:sun:sunos:4.0.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0217</vuln:cve-id>
        <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:01.790-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0249">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:microsoft:windows_nt</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0249</vuln:cve-id>
        <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:04.273-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>Windows NT RSHSVC program allows remote users to execute arbitrary commands.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0251">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:talkd:talkd" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:talkd:talkd</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0251</vuln:cve-id>
        <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:04.413-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>Denial of service in talk program allows remote attackers to disrupt a user's display.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0252">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:lsoft:listserv" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:lsoft:listserv</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0252</vuln:cve-id>
        <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:08.337-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:summary>Buffer overflow in listserv allows arbitrary command execution.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0253">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:3.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:internet_information_server:2.0</vuln:product>
            <vuln:product>cpe:/a:microsoft:internet_information_server:3.0</vuln:product>
            <vuln:product>cpe:/a:microsoft:internet_information_server:1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0253</vuln:cve-id>
        <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:08.397-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0204">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.6.9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:eric_allman:sendmail:8.6.9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0204</vuln:cve-id>
        <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:00.773-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:summary>Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0201">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ftp:ftp" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ftp:ftp</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0201</vuln:cve-id>
        <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:00.197-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>6.4</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:summary>A quote cwd command on FTP servers can reveal the full path of the home directory of the "ftp" user.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0202">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0202</vuln:cve-id>
        <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:34:00.647-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:summary>The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0178">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:oreilly:oreilly_website:1.1e" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:oreilly:oreilly_website:1.1e</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0178</vuln:cve-id>
        <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:54.540-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/295">http-website-winsample(295)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/2078">2078</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/8">8</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/bugtraq/1997_1/0021.html">19970106 Re: signal handling</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0179">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_95" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_95</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0179</vuln:cve-id>
        <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:54.647-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MSKB</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q140818">Q140818</vuln:reference>
        </vuln:references>
        <vuln:summary>Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0180">
        <vuln:cve-id>CVE-1999-0180</vuln:cve-id>
        <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:54.727-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:summary>in.rshd allows users to login with a NULL username and execute commands.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0173">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:matt_wright:formmail" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:matt_wright:formmail</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0173</vuln:cve-id>
        <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-09T08:33:54.103-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector 