<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" nvd_xml_version="2.0" pub_date="2009-11-07T04:00:00" xsi:schemaLocation="http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
    <entry id="CVE-2003-0061">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0061</vuln:cve-id>
        <vuln:published-datetime>2002-01-11T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:21.787-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-25T11:27:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>IDEFENSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/application/poi/display?id=87&amp;type=vulnerabilities&amp;flashstatus=true">20030203 HP UX passwd Binary Buffer Overflow Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.</vuln:summary>
    </entry>
    <entry id="CVE-2003-1071">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:7.0</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-1071</vuln:cve-id>
        <vuln:published-datetime>2003-01-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:21:39.397-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-24T11:59:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/944241">VU#944241</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11608">solaris-wall-message-spoofing(11608)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-51980-1">51980</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/305105">20030103 Solaris 2.x /usr/sbin/wall Advisory</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/7825/">7825</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1006682">1006682</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1005882">1005882</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6509">6509</vuln:reference>
        </vuln:references>
        <vuln:summary>rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to come from arbitrary user IDs by closing stderr before executing wall, then supplying a spoofed from header.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0014">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:bmv:bmv:1.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:bmv:bmv:1.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0014</vuln:cve-id>
        <vuln:published-datetime>2003-01-11T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:13.773-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-25T12:12:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18823">bmv-symlink(18823)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityfocus.org/bid/12229">12229</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-633">DSA-633</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://packages.debian.org/changelogs/pool/main/b/bmv/bmv_1.2-14.2/changelog">http://packages.debian.org/changelogs/pool/main/b/bmv/bmv_1.2-14.2/changelog</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012847">1012847</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13796">13796</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13793">13793</vuln:reference>
        </vuln:references>
        <vuln:summary>gsinterf.c in bmv 1.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0032">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5.1_r4" />
                <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5_.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5_.0</vuln:product>
            <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5.1_r4</vuln:product>
            <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5.2</vuln:product>
            <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0032</vuln:cve-id>
        <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:24.807-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-228">DSA-228</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104162752401212&amp;w=2">20030103 Multiple libmcrypt vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/10988.php">libmcrypt-libtool-memory-leak(10988)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6512">6512</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104188513728573&amp;w=2">20030105 GLSA:  libmcrypt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000567">CLA-2003:567</vuln:reference>
        </vuln:references>
        <vuln:summary>Memory leak in libmcrypt before 2.5.5 allows attackers to cause a denial of service (memory exhaustion) via a large number of requests to the application, which causes libmcrypt to dynamically load algorithms via libtool.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0031">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5.1_r4" />
                <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5_.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5_.0</vuln:product>
            <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5.1_r4</vuln:product>
            <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5.2</vuln:product>
            <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0031</vuln:cve-id>
        <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:24.727-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-228">DSA-228</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104162752401212&amp;w=2">20030103 Multiple libmcrypt vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1006181">1006181</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6510">6510</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104188513728573&amp;w=2">20030105 GLSA:  libmcrypt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000567">CLA-2003:567</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple buffer overflows in libmcrypt before 2.5.5 allow attackers to cause a denial of service (crash).</vuln:summary>
    </entry>
    <entry id="CVE-2003-0013">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:bugzilla:2.14.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:bugzilla:2.14.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:bugzilla:2.17.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:bugzilla:2.16.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:bugzilla:2.16</vuln:product>
            <vuln:product>cpe:/a:mozilla:bugzilla:2.17</vuln:product>
            <vuln:product>cpe:/a:mozilla:bugzilla:2.14.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:bugzilla:2.14.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:bugzilla:2.14</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0013</vuln:cve-id>
        <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:22.697-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-230">DSA-230</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104154319200399&amp;w=2">20030102 [BUGZILLA] Security Advisory - remote database password disclosure</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6501">6501</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/6351">6351</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/10970.php">bugzilla-htaccess-database-password(10970)</vuln:reference>
        </vuln:references>
        <vuln:summary>The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of the localconfig file that are made from editors such as vi and Emacs, which could allow remote attackers to obtain a database password by directly accessing the backup file.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0012">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:bugzilla:2.14.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:bugzilla:2.14.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:bugzilla:2.17.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:bugzilla:2.16.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:bugzilla:2.16</vuln:product>
            <vuln:product>cpe:/a:mozilla:bugzilla:2.17</vuln:product>
            <vuln:product>cpe:/a:mozilla:bugzilla:2.14.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:bugzilla:2.14.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:bugzilla:2.14</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0012</vuln:cve-id>
        <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:22.617-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104154319200399&amp;w=2">20030102 [BUGZILLA] Security Advisory - remote database password disclosure</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/10971.php">bugzilla-mining-world-writable(10971)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6502">6502</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-012.html">RHSA-2003:012</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-230">DSA-230</vuln:reference>
        </vuln:references>
        <vuln:summary>The data collection script for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 sets world-writable permissions for the data/mining directory when it runs, which allows local users to modify or delete the data.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0026">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0" />
                <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc1" />
                <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc2" />
                <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc3" />
                <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc4" />
                <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc5" />
                <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc6" />
                <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc7" />
                <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc8" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc1</vuln:product>
            <vuln:product>cpe:/a:isc:dhcpd:3.0</vuln:product>
            <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc2</vuln:product>
            <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc8</vuln:product>
            <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc7</vuln:product>
            <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc4</vuln:product>
            <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc3</vuln:product>
            <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc6</vuln:product>
            <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0026</vuln:cve-id>
        <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:17:25.460-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/284857">VU#284857</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-2003-01.html">CA-2003-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-011.html">RHSA-2003:011</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-231">DSA-231</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11073">dhcpd-minires-multiple-bo(11073)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.suse.com/de/security/2003_006_dhcp.html">SuSE-SA:2003:006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1005924">1005924</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6627">6627</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENPKG</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.002.html">OpenPKG-SA-2003.002</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:007">MDKSA-2003:007</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/n-031.shtml">N-031</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000562">CLA-2003:562</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0250.html">20030122 [securityslackware.com: [slackware-security] New DHCP packages available]</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple stack-based buffer overflows in the error handling routines of the minires library, as used in the NSUPDATE capability for ISC DHCPD 3.0 through 3.0.1RC10, allow remote attackers to execute arbitrary code via a DHCP message containing a long hostname.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0025">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2" />
                <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.5" />
                <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.6" />
                <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.7" />
                <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.8" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:horde:imp:2.2.8</vuln:product>
            <vuln:product>cpe:/a:horde:imp:2.2.6</vuln:product>
            <vuln:product>cpe:/a:horde:imp:2.2.7</vuln:product>
            <vuln:product>cpe:/a:horde:imp:2.2.4</vuln:product>
            <vuln:product>cpe:/a:horde:imp:2.2.5</vuln:product>
            <vuln:product>cpe:/a:horde:imp:2.2.2</vuln:product>
            <vuln:product>cpe:/a:horde:imp:2.2.3</vuln:product>
            <vuln:product>cpe:/a:horde:imp:2.2.1</vuln:product>
            <vuln:product>cpe:/a:horde:imp:2.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0025</vuln:cve-id>
        <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:24.023-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-229">DSA-229</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104204786206563&amp;w=2">20030108 IMP 2.x SQL injection vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1005904">1005904</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6559">6559</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/306268">20030108 Re: IMP 2.x SQL injection vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/8177">8177</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/8087">8087</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using mailbox.php3.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0001">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.2" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp1" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp2" />
                <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5" />
                <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.1" />
                <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.2" />
                <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.3" />
                <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.2</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp1</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp2</vuln:product>
            <vuln:product>cpe:/o:netbsd:netbsd:1.5.2</vuln:product>
            <vuln:product>cpe:/o:netbsd:netbsd:1.5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
            <vuln:product>cpe:/o:netbsd:netbsd:1.6</vuln:product>
            <vuln:product>cpe:/o:netbsd:netbsd:1.5.3</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
            <vuln:product>cpe:/o:netbsd:netbsd:1.5.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0001</vuln:cve-id>
        <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:17:21.290-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:2665" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2665" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/412115">VU#412115</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-025.html">RHSA-2003:025</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf">http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>ATSTAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.atstake.com/research/advisories/2003/a010603-1.txt">A010603-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104222046632243&amp;w=2">20030110 More information regarding Etherleak</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0016.html">20030110 More information regarding Etherleak</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/307564/30/26270/threaded">20030117 Re: More information regarding Etherleak</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/305335/30/26420/threaded">20030106 Etherleak: Ethernet frame padding information leakage (A010603-1)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-088.html">RHSA-2003:088</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/9962">9962</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/7996">7996</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.</vuln:summary>
    </entry>
    <entry id="CVE-2003-1075">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:7.0</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-1075</vuln:cve-id>
        <vuln:published-datetime>2003-01-27T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:21:42.103-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-24T11:43:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50240-1">50240</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/7968/">7968</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11186">solaris-ftpd-dos(11186)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1005996">1005996</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6709">6709</vuln:reference>
        </vuln:references>
        <vuln:summary>Unknown vulnerability in the FTP server (in.ftpd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (temporary FTP server hang), which affects other active mode FTP clients.</vuln:summary>
    </entry>
    <entry id="CVE-2003-1090">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:celestial_software:absolutetelnet:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:celestial_software:absolutetelnet:2.11" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:celestial_software:absolutetelnet:2.0</vuln:product>
            <vuln:product>cpe:/a:celestial_software:absolutetelnet:2.11</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-1090</vuln:cve-id>
        <vuln:published-datetime>2003-02-06T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:36:00.967-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-24T10:49:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/666073">VU#666073</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11265">absolutetelnet-title-bar-bo(11265)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6785">6785</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104454984001076&amp;w=2">20030206 AbsoluteTelnet 2.00 buffer overflow.</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/16024">16024</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window title.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0027">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0:x86_update_2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:7.0</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:9.0:x86_update_2</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0027</vuln:cve-id>
        <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:24.493-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:2592" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2592" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:195" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:195" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:120" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:120" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/850785">VU#850785</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.entercept.com/news/uspr/01-22-03.asp">http://www.entercept.com/news/uspr/01-22-03.asp</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11129">solaris-kcms-directory-traversal(11129)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6665">6665</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/50104">50104</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104326556329850&amp;w=2">20030122 Entercept Ricochet Advisory: Sun Solaris KCMS Library Service Daemon Arbitrary File Retrieval Vulner</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0017">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0017</vuln:cve-id>
        <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:17:23.493-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2">http://marc.theaimsgroup.com/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2</vuln:reference>
        </vuln:references>
        <vuln:summary>Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0016">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0016</vuln:cve-id>
        <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:23.040-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/979793">VU#979793</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/825177">VU#825177</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2">[apache-httpd-announce] 20030120 [ANNOUNCE] Apache 2.0.44 Released</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.apacheweek.com/issues/03-01-24#security">http://www.apacheweek.com/issues/03-01-24#security</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11125">apache-device-code-execution(11125)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11124">apache-device-name-dos(11124)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6659">6659</vuln:reference>
        </vuln:references>
        <vuln:summary>Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0015">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.10.7" />
                <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.10.8" />
                <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11" />
                <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.1" />
                <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.1p1" />
                <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.2" />
                <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.3" />
                <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:freebsd:freebsd:4.7</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.6</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.5</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.4</vuln:product>
            <vuln:product>cpe:/a:cvs:cvs:1.11.1</vuln:product>
            <vuln:product>cpe:/a:cvs:cvs:1.11.1p1</vuln:product>
            <vuln:product>cpe:/a:cvs:cvs:1.11.2</vuln:product>
            <vuln:product>cpe:/a:cvs:cvs:1.10.7</vuln:product>
            <vuln:product>cpe:/a:cvs:cvs:1.10.8</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.0</vuln:product>
            <vuln:product>cpe:/a:cvs:cvs:1.11.3</vuln:product>
            <vuln:product>cpe:/a:cvs:cvs:1.11</vuln:product>
            <vuln:product>cpe:/a:cvs:cvs:1.11.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0015</vuln:cve-id>
        <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:22.960-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/650937">VU#650937</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-2003-02.html">CA-2003-02</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.e-matters.de/advisories/012003.html">http://security.e-matters.de/advisories/012003.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://rhn.redhat.com/errata/RHSA-2003-013.html">RHSA-2003:013</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11108">cvs-doublefree-memory-corruption(11108)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6650">6650</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-012.html">RHSA-2003:012</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:009">MDKSA-2003:009</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-233">DSA-233</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/n-032.shtml">N-032</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FREEBSD</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104438807203491&amp;w=2">FreeBSD-SA-03:01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104428571204468&amp;w=2">20030202 Exploit for CVS double free() for Linux pserver</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104342550612736&amp;w=2">20030124 Test program for CVS double-free.</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104333092200589&amp;w=2">20030122 [security@slackware.com: [slackware-security] New CVS packages available]</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://ccvs.cvshome.org/servlets/NewsItemView?newsID=51&amp;JServSessionIdservlets=5of2iuhr14">http://ccvs.cvshome.org/servlets/NewsItemView?newsID=51&amp;JServSessionIdservlets=5of2iuhr14</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0028.html">20030120 Advisory 01/2003: CVS remote vulnerability</vuln:reference>
        </vuln:references>
        <vuln:summary>Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-prog commands.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0003">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server:jp" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp1" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp2" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp3" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000:::server:jp</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp1</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp2</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp3</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0003</vuln:cve-id>
        <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:22.163-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:103" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:103" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/610986">VU#610986</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-2003-03.html">CA-2003-03</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MS</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.microsoft.com/technet/security/bulletin/ms03-001.asp">MS03-001</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11132">win-locator-bo(11132)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6666">6666</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>NTBUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104393588232166&amp;w=2">20030130 Microsoft RPC Locator Buffer Overflow Vulnerability (#NISR29012003)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104394414713415&amp;w=2">20030130 Microsoft RPC Locator Buffer Overflow Vulnerability (#NISR29012003)</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0002">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:microsoft:content_management_server:2001" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:content_management_server:2001:sp1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:content_management_server:2001:sp1</vuln:product>
            <vuln:product>cpe:/a:microsoft:content_management_server:2001</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0002</vuln:cve-id>
        <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:22.087-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MS</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.microsoft.com/technet/security/bulletin/ms03-002.asp">MS03-002</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/10318.php">mcms-manuallogin-reasontxt-xss (10318)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=103417794800719&amp;w=2">20021007 CSS on Microsoft Content Management Server</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/5922">5922</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0007">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002:sp1" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002:sp2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:outlook:2002:sp2</vuln:product>
            <vuln:product>cpe:/a:microsoft:outlook:2002:sp1</vuln:product>
            <vuln:product>cpe:/a:microsoft:outlook:2002</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0007</vuln:cve-id>
        <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:22.320-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MS</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.microsoft.com/technet/security/bulletin/ms03-003.asp">MS03-003</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11133">outlook-v1-certificate-plaintext(11133)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6667">6667</vuln:reference>
        </vuln:references>
        <vuln:summary>Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure."</vuln:summary>
    </entry>
    <entry id="CVE-2003-0039">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc1" />
                <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc10" />
                <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc2" />
                <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc3" />
                <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc4" />
                <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc5" />
                <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc6" />
                <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc7" />
                <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc8" />
                <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc1</vuln:product>
            <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc2</vuln:product>
            <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc10</vuln:product>
            <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc8</vuln:product>
            <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc7</vuln:product>
            <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc9</vuln:product>
            <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc4</vuln:product>
            <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc3</vuln:product>
            <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc6</vuln:product>
            <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0039</vuln:cve-id>
        <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:18.257-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/149953">VU#149953</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-245">DSA-245</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104310927813830&amp;w=2">20030115 DoS against DHCP infrastructure with isc dhcrelay</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11187">dhcp-dhcrelay-dos(11187)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6628">6628</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-034.html">RHSA-2003:034</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openpkg.org/security/OpenPKG-SA-2003.012-dhcpd.html">20030219 [OpenPKG-SA-2003.012] OpenPKG Security Advisory (dhcpd)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000616">CLSA-2003:616</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TURBO</vuln:source>
            <vuln:reference xml:lang="en" href="http://cc.turbolinux.com/security/TLSA-2003-26.txt">TLSA-2003-26</vuln:reference>
        </vuln:references>
        <vuln:summary>ISC dhcrelay (dhcp-relay) 3.0rc9 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (packet storm) via a certain BOOTP packet that is forwarded to a broadcast MAC address, causing an infinite loop that is not restricted by a hop count.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0038">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:gnu:mailman:2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0038</vuln:cve-id>
        <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:18.117-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-436">DSA-436</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://telia.dl.sourceforge.net/sourceforge/mailman/xss-2.1.0-patch.txt">http://telia.dl.sourceforge.net/sourceforge/mailman/xss-2.1.0-patch.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104342745916111">20030124 Mailman: cross-site scripting bug</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11152">mailman-email-variable-xss(11152)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1005987">1005987</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6677">6677</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/9205">9205</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0037">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:noffle:noffle:1.0.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:noffle:noffle:1.0.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0037</vuln:cve-id>
        <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:25.163-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-244">DSA-244</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11181">noffle-multiple-bo(11181)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6695">6695</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/7955">7955</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflows in noffle news server 1.0.1 and earlier allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0036">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:rildo_pragana:ml85p" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:rildo_pragana:ml85p</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0036</vuln:cve-id>
        <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:17:26.397-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>6.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/advisory/01.21.03.txt">http://www.idefense.com/advisory/01.21.03.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1005959">1005959</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/307608/30/26270/threaded">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010">MDKSA-2003:010</vuln:reference>
        </vuln:references>
        <vuln:summary>ml85p, as included in the printer-drivers package for Mandrake Linux, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable filenames of the form "mlg85p%d".</vuln:summary>
    </entry>
    <entry id="CVE-2003-0035">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:robert_krawitz:escputil:1.15.2.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:robert_krawitz:escputil:1.15.2.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0035</vuln:cve-id>
        <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:25.023-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/advisory/01.21.03.txt">http://www.idefense.com/advisory/01.21.03.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1005959">1005959</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6658">6658</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/307608/30/26270/threaded">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010">MDKSA-2003:010</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in escputil, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long printer-name command line argument.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0034">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:jean-jacques_sarton:mtink:0.9.32" />
                <cpe-lang:fact-ref name="cpe:/a:jean-jacques_sarton:mtink:0.9.33" />
                <cpe-lang:fact-ref name="cpe:/a:jean-jacques_sarton:mtink:0.9.52" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:jean-jacques_sarton:mtink:0.9.32</vuln:product>
            <vuln:product>cpe:/a:jean-jacques_sarton:mtink:0.9.33</vuln:product>
            <vuln:product>cpe:/a:jean-jacques_sarton:mtink:0.9.52</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0034</vuln:cve-id>
        <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:24.947-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/advisory/01.21.03.txt">http://www.idefense.com/advisory/01.21.03.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1005959">1005959</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6656">6656</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010">MDKSA-2003:010</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long HOME environment variable.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0045">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.0" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:tomcat:3.3</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.3.1</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.2.3</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.2.4</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.1.1</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.0</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.2.1</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.1</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0045</vuln:cve-id>
        <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:19.257-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/12102">jakarta-tomcat-msdos-dos(12102)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0044">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.0" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3.1a" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:tomcat:3.3</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.3.1a</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.3.1</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.2.3</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.2.4</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.1.1</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.0</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.2.1</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.1</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0044</vuln:cve-id>
        <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:26.087-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-246">DSA-246</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/advisories/5111">HPSBUX0303-249</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11196">tomcat-web-app-xss(11196)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6720">6720</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/9204">9204</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/9203">9203</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/n-060.shtml">N-060</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/7972">7972</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0043">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.0" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:tomcat:3.3</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.3.1</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.2.3</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.2.4</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.1.1</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.0</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.2.1</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.1</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0043</vuln:cve-id>
        <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:26.023-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11195">tomcat-webxml-read-files(11195)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6722">6722</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/advisories/5111">HPSBUX0303-249</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-246">DSA-246</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/n-060.shtml">N-060</vuln:reference>
        </vuln:references>
        <vuln:summary>Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0042">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.0" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:tomcat:3.3</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.3.1</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.2.3</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.2.4</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.1.1</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.0</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.2.1</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.1</vuln:product>
            <vuln:product>cpe:/a:apache:tomcat:3.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0042</vuln:cve-id>
        <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:25.947-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-246">DSA-246</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104394568616290&amp;w=2">20030130 Apache Jakarta Tomcat 3 URL parsing vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11194">tomcat-null-directory-listing(11194)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6721">6721</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/advisories/5111">HPSBUX0303-249</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/n-060.shtml">N-060</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/7977">7977</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/7972">7972</vuln:reference>
        </vuln:references>
        <vuln:summary>Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.</vuln:summary>
    </entry>
    <entry id="CVE-2003-1080">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:cve-id>CVE-2003-1080</vuln:cve-id>
        <vuln:published-datetime>2003-02-11T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:21:42.867-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>1.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-24T11:21:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11303">solaris-mail-unauthorized-access(11303)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50751-1">50751</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/8058/">8058</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1006084">1006084</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6838">6838</vuln:reference>
        </vuln:references>
        <vuln:summary>Unknown vulnerability in mail for Solaris 2.6 through 9 allows local users to read the email of other users.</vuln:summary>
    </entry>
    <entry id="CVE-2003-1079">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:7.0</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-1079</vuln:cve-id>
        <vuln:published-datetime>2003-02-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:21:42.727-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-24T11:27:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11368">solaris-udp-rpc-dos(11368)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50626-1">50626</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/8092/">8092</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1006131">1006131</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6883">6883</vuln:reference>
        </vuln:references>
        <vuln:summary>Unknown vulnerability in UDP RPC for Solaris 2.5.1 through 9 for SPARC, and 2.5.1 through 8 for x86, allows remote attackers to cause a denial of service (memory consumption) via certain arguments in RPC calls that cause large amounts of memory to be allocated.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0048">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:putty:putty:0.48" />
                <cpe-lang:fact-ref name="cpe:/a:putty:putty:0.49" />
                <cpe-lang:fact-ref name="cpe:/a:putty:putty:0.53" />
                <cpe-lang:fact-ref name="cpe:/a:putty:putty:0.53b" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:putty:putty:0.53b</vuln:product>
            <vuln:product>cpe:/a:putty:putty:0.53</vuln:product>
            <vuln:product>cpe:/a:putty:putty:0.49</vuln:product>
            <vuln:product>cpe:/a:putty:putty:0.48</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0048</vuln:cve-id>
        <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:26.570-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/advisory/01.28.03.txt">http://www.idefense.com/advisory/01.28.03.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1006014">1006014</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6724">6724</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386492422014&amp;w=2">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</vuln:reference>
        </vuln:references>
        <vuln:summary>PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0047">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:van_dyke_technologies:securecrt:3.4.7" />
                <cpe-lang:fact-ref name="cpe:/a:van_dyke_technologies:securecrt:4.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:van_dyke_technologies:securefx:2.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:van_dyke_technologies:securefx:2.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:van_dyke_technologies:entunnel:1.0.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:van_dyke_technologies:securefx:2.0.4</vuln:product>
            <vuln:product>cpe:/a:van_dyke_technologies:securefx:2.1.2</vuln:product>
            <vuln:product>cpe:/a:van_dyke_technologies:securecrt:4.0.2</vuln:product>
            <vuln:product>cpe:/a:van_dyke_technologies:entunnel:1.0.2</vuln:product>
            <vuln:product>cpe:/a:van_dyke_technologies:securecrt:3.4.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0047</vuln:cve-id>
        <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:26.493-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/advisory/01.28.03.txt">http://www.idefense.com/advisory/01.28.03.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386492422014&amp;w=2">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1006012">1006012</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1006011">1006011</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1006010">1006010</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6728">6728</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6727">6727</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6726">6726</vuln:reference>
        </vuln:references>
        <vuln:summary>SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0046">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:celestial_software:absolutetelnet:2.11" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:celestial_software:absolutetelnet:2.11</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0046</vuln:cve-id>
        <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:26.413-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/advisory/01.28.03.txt">http://www.idefense.com/advisory/01.28.03.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.celestialsoftware.net/telnet/beta_software.html">http://www.celestialsoftware.net/telnet/beta_software.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386492422014&amp;w=2">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1006013">1006013</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6725">6725</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/7686">7686</vuln:reference>
        </vuln:references>
        <vuln:summary>AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0019">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0::i386" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:redhat:linux:8.0::i386</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0019</vuln:cve-id>
        <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:23.557-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/134025">VU#134025</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-056.html">RHSA-2003:056</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11276.php">linux-umlnet-gain-privileges(11276)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6801">6801</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/n-044.shtml">N-044</vuln:reference>
        </vuln:references>
        <vuln:summary>uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0018">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0018</vuln:cve-id>
        <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:23.477-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>3.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-025.html">RHSA-2003:025</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-423">DSA-423</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11249.php">linux-odirect-information-leak(11249)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6763">6763</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:014">MDKSA-2003:014</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-358">DSA-358</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://linux.bkbits.net:8080/linux-2.4/cset@3e2f193drGJDBg9SG6JwaDQwCBnAMQ">http://linux.bkbits.net:8080/linux-2.4/cset@3e2f193drGJDBg9SG6JwaDQwCBnAMQ</vuln:reference>
        </vuln:references>
        <vuln:summary>Linux kernel 2.4.10 through 2.4.21-pre4 does not properly handle the O_DIRECT feature, which allows local attackers with write privileges to read portions of previously deleted files, or cause file system corruption.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0041">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos_ftp_client" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux:6.2::i386" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.0::i386" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.1::i386" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2::i386" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2::ia64" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.3::i386" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0::i386" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:redhat:linux:7.3::i386</vuln:product>
            <vuln:product>cpe:/o:redhat:linux:7.0::i386</vuln:product>
            <vuln:product>cpe:/o:redhat:linux:8.0::i386</vuln:product>
            <vuln:product>cpe:/o:redhat:linux:7.2::i386</vuln:product>
            <vuln:product>cpe:/o:redhat:linux:7.1::i386</vuln:product>
            <vuln:product>cpe:/o:redhat:linux:6.2::i386</vuln:product>
            <vuln:product>cpe:/o:redhat:linux:7.2::ia64</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos_ftp_client</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0041</vuln:cve-id>
        <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:17:27.977-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-020.html">RHSA-2003:020</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0047.html">20030128 MIT Kerberos FTP client remote shell commands execution</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:021">MDKSA-2003:021</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/8114">8114</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/7979">7979</vuln:reference>
        </vuln:references>
        <vuln:summary>Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0040">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:double_precision_incorporated:courier_mta:0.37.3" />
                <cpe-lang:fact-ref name="cpe:/a:inter7:courier-imap:1.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:inter7:courier-imap:1.6</vuln:product>
            <vuln:product>cpe:/a:double_precision_incorporated:courier_mta:0.37.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0040</vuln:cve-id>
        <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:18.427-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6738">6738</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-247">DSA-247</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11213">courierimap-authmysqllib-sql-injection(11213)</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0004">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0004</vuln:cve-id>
        <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:22.243-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MS</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.microsoft.com/technet/security/bulletin/ms03-005.asp">MS03-005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6778">6778</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11260.php">winxp-windows-redirector-bo(11260)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878038418534&amp;w=2">20030327 NSFOCUS SA2003-01: Microsoft Windows XP Redirector Local Buffer Overflow Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0154.html">20030327 NSFOCUS SA2003-01: Microsoft Windows XP Redirector Local Buffer Overflow Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the Windows Redirector function in Microsoft Windows XP allows local users to execute arbitrary code via a long parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0056">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:slocate:slocate:2.5" />
                <cpe-lang:fact-ref name="cpe:/a:slocate:slocate:2.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:slocate:slocate:2.5</vuln:product>
            <vuln:product>cpe:/a:slocate:slocate:2.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0056</vuln:cve-id>
        <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:17:45.587-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-252">DSA-252</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104428624705363&amp;w=2">20030202 GLSA:  slocate</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.usg.org.uk/advisories/2003.001.txt">http://www.usg.org.uk/advisories/2003.001.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.net-security.org/advisory.php?id=2010">CLA-2003:643</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:015">MDKSA-2003:015</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/8749">8749</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/8236">8236</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/8118/">8118</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/8007">8007</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/7982">7982</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/7947">7947</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10720">10720</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://rhn.redhat.com/errata/RHSA-2004-041.html">RHSA-2004:041</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104348607205691&amp;w=2">20030125 Re: [USG- SA- 2003.001] USG Security Advisory (slocate)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104342864418213&amp;w=2">20030124 [USG- SA- 2003.001] USG Security Advisory (slocate)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CALDERA</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-009.0.txt">CSSA-2003-009.0</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or (2) -r command line argument.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0057">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.0b25" />
                <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.1.5" />
                <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.1_.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:hypermail:hypermail:2.1_.0</vuln:product>
            <vuln:product>cpe:/a:hypermail:hypermail:2.1.5</vuln:product>
            <vuln:product>cpe:/a:hypermail:hypermail:2.0b25</vuln:product>
            <vuln:product>cpe:/a:hypermail:hypermail:2.1.1</vuln:product>
            <vuln:product>cpe:/a:hypermail:hypermail:2.1.2</vuln:product>
            <vuln:product>cpe:/a:hypermail:hypermail:2.1.3</vuln:product>
            <vuln:product>cpe:/a:hypermail:hypermail:2.1.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0057</vuln:cve-id>
        <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:41.993-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104369136703903&amp;w=2">20030127 Hypermail buffer overflows</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11158">hypermail-long-hostname-bo(11158)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11157">hypermail-mail-attachment-bo(11157)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6690">6690</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6689">6689</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-248">DSA-248</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/8030">8030</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0042.html">20030126 Hypermail buffer overflows</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple buffer overflows in Hypermail 2 before 2.1.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code (1) via a long attachment filename that is not properly handled by the hypermail executable, or (2) by connecting to the mail CGI program from an IP address that reverse-resolves to a long hostname.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0058">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:sun:enterprise_authentication_mechanism:1.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.2.4</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.2.1</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.2.2</vuln:product>
            <vuln:product>cpe:/a:sun:enterprise_authentication_mechanism:1.0</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.2.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0058</vuln:cve-id>
        <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:21.317-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1110" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1110" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/661243">VU#661243</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6683">6683</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/10099">kerberos-kdc-null-pointer-dos(10099)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-168.html">RHSA-2003:168</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:043">MDKSA-2003:043</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/50142">50142</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639">CLSA-2003:639</vuln:reference>
        </vuln:references>
        <vuln:summary>MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0059">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mit:kerberos:5-1.2.1</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.2.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0059</vuln:cve-id>
        <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:21.490-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/684563">VU#684563</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6714">6714</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11188">kerberos-kdc-user-spoofing(11188)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-168.html">RHSA-2003:168</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:043">MDKSA-2003:043</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639">CLSA-2003:639</vuln:reference>
        </vuln:references>
        <vuln:summary>Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0060">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mit:kerberos:5-1.2.4</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.2.1</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.2.2</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.2.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0060</vuln:cve-id>
        <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:21.630-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/787523">VU#787523</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6712">6712</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11189">kerberos-kdc-format-string(11189)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/4879">4879</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639">CLSA-2003:639</vuln:reference>
        </vuln:references>
        <vuln:summary>Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0062">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:eset_software:nod32_antivirus:1.0.11" />
                <cpe-lang:fact-ref name="cpe:/a:eset_software:nod32_antivirus:1.0.12" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:eset_software:nod32_antivirus:1.0.11</vuln:product>
            <vuln:product>cpe:/a:eset_software:nod32_antivirus:1.0.12</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0062</vuln:cve-id>
        <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:42.383-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/advisory/02.10.03.txt">http://www.idefense.com/advisory/02.10.03.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6803">6803</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11282.php">nod32-pathname-bo(11282)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104490777824360&amp;w=2">20030210 iDEFENSE Security Advisory 02.10.03: Buffer Overflow In NOD32 Antivirus Software for Unix</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in Eset Software NOD32 for UNIX before 1.013 allows local users to execute arbitrary code via a long path name.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0073">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.31" />
                <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.36" />
                <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.41" />
                <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.47" />
                <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.52" />
                <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.53" />
                <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.54" />
                <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.54a" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mysql:mysql:3.23.47</vuln:product>
            <vuln:product>cpe:/a:mysql:mysql:3.23.31</vuln:product>
            <vuln:product>cpe:/a:mysql:mysql:3.23.54a</vuln:product>
            <vuln:product>cpe:/a:mysql:mysql:3.23.52</vuln:product>
            <vuln:product>cpe:/a:mysql:mysql:3.23.53</vuln:product>
            <vuln:product>cpe:/a:mysql:mysql:3.23.54</vuln:product>
            <vuln:product>cpe:/a:mysql:mysql:3.23.41</vuln:product>
            <vuln:product>cpe:/a:mysql:mysql:3.23.36</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0073</vuln:cve-id>
        <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:44.320-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:436" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:436" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-303">DSA-303</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104385719107879&amp;w=2">20030129 [OpenPKG-SA-2003.008] OpenPKG Security Advisory (mysql)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mysql.com/doc/en/News-3.23.55.html">http://www.mysql.com/doc/en/News-3.23.55.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6718">6718</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-166.html">RHSA-2003:166</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-094.html">RHSA-2003:094</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-093.html">RHSA-2003:093</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:013">MDKSA-2003:013</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>ENGARDE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.linuxsecurity.com/advisories/engarde_advisory-2873.html">ESA-20030220-004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11199.php">mysql-mysqlchangeuser-doublefree-dos(11199)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000743">CLA-2003:743</vuln:reference>
        </vuln:references>
        <vuln:summary>Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0074">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:plptools:plptools:0.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:plptools:plptools:0.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0074</vuln:cve-id>
        <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:24.083-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6715">6715</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11193.php">plptools-plpnsfd-format-string(11193)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386699725019&amp;w=2">20030129 Re: Local root vuln in SuSE 8.0 plptools package</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104385772908969&amp;w=2">20030129 Local root vuln in SuSE 8.0 plptools package</vuln:reference>
        </vuln:references>
        <vuln:summary>Format string vulnerability in mpmain.c for plpnfsd of the plptools package allows remote attackers to execute arbitrary code via the functions (1) debuglog, (2) errorlog, and (3) infolog.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0075">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:bladeenc:bladeenc:0.92.7" />
                <cpe-lang:fact-ref name="cpe:/a:bladeenc:bladeenc:0.93.10" />
                <cpe-lang:fact-ref name="cpe:/a:bladeenc:bladeenc:0.94.0" />
                <cpe-lang:fact-ref name="cpe:/a:bladeenc:bladeenc:0.94.1" />
                <cpe-lang:fact-ref name="cpe:/a:bladeenc:bladeenc:0.94.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:bladeenc:bladeenc:0.93.10</vuln:product>
            <vuln:product>cpe:/a:bladeenc:bladeenc:0.94.0</vuln:product>
            <vuln:product>cpe:/a:bladeenc:bladeenc:0.94.2</vuln:product>
            <vuln:product>cpe:/a:bladeenc:bladeenc:0.94.1</vuln:product>
            <vuln:product>cpe:/a:bladeenc:bladeenc:0.92.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0075</vuln:cve-id>
        <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:24.240-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6745">6745</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.pivx.com/luigi/adv/blade942-adv.txt">http://www.pivx.com/luigi/adv/blade942-adv.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104446346127432&amp;w=2">GLSA-200302-04</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11227.php">bladeenc-myfseek-code-execution(11227)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104428700106672&amp;w=2">20030202 Bladeenc 0.94.2 code execution</vuln:reference>
        </vuln:references>
        <vuln:summary>Integer signedness error in the myFseek function of samplein.c for Blade encoder (BladeEnc) 0.94.2 and earlier allows remote attackers to execute arbitrary code via a negative offset value following a "fmt" wave chunk.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0076">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:dcgui:dcgui:0.2" />
                <cpe-lang:fact-ref name="cpe:/a:dcgui:dcgui:0.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:qt-dcgui:qt-dcgui:0.2" />
                <cpe-lang:fact-ref name="cpe:/a:qt-dcgui:qt-dcgui:0.2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:dcgui:dcgui:0.2</vuln:product>
            <vuln:product>cpe:/a:qt-dcgui:qt-dcgui:0.2.1</vuln:product>
            <vuln:product>cpe:/a:dcgui:dcgui:0.2.1</vuln:product>
            <vuln:product>cpe:/a:qt-dcgui:qt-dcgui:0.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0076</vuln:cve-id>
        <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:24.443-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>6.4</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104437720116243&amp;w=2">20030204 GLSA:  qt-dcgui</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11246.php">qtdcgui-directory-download-files(11246)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://dc.ketelhot.de/pipermail/dc/2003-January/000094.html">http://dc.ketelhot.de/pipermail/dc/2003-January/000094.html</vuln:reference>
        </vuln:references>
        <vuln:summary>Unknown vulnerability in the directory parser for Direct Connect 4 Linux (dcgui) before 0.2.2 allows remote attackers to read files outside the sharelist.</vuln:summary>
    </entry>
    <entry id="CVE-2003-1326">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-1326</vuln:cve-id>
        <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:23:32.257-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:49" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:49" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:178" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:178" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:126" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:126" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MS</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.microsoft.com/technet/security/bulletin/ms03-004.asp">MS03-004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11258.php">ie-dialog-zone-bypass(11258)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6779">6779</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/n-038.shtml">N-038</vuln:reference>
        </vuln:references>
        <vuln:summary>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."</vuln:summary>
    </entry>
    <entry id="CVE-2003-1326">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-1326</vuln:cve-id>
        <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:23:32.257-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:49" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:49" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:178" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:178" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:126" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:126" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MS</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.microsoft.com/technet/security/bulletin/ms03-004.asp">MS03-004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11258.php">ie-dialog-zone-bypass(11258)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6779">6779</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/n-038.shtml">N-038</vuln:reference>
        </vuln:references>
        <vuln:summary>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."</vuln:summary>
    </entry>
    <entry id="CVE-2003-1078">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:7.0</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-1078</vuln:cve-id>
        <vuln:published-datetime>2003-02-28T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:21:42.587-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-24T11:31:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11436">solaris-ftp-plaintext-password(11436)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-51081-1">51081</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/8186/">8186</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1006195">1006195</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6989">6989</vuln:reference>
        </vuln:references>
        <vuln:summary>The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password on the screen during login.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0021">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:michael_jennings:eterm:0.8.10" />
                <cpe-lang:fact-ref name="cpe:/a:michael_jennings:eterm:0.9.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:michael_jennings:eterm:0.8.10</vuln:product>
            <vuln:product>cpe:/a:michael_jennings:eterm:0.9.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0021</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:23.727-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11413.php">terminal-emulator-screen-dump(11413)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6936">6936</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:040">MDKSA-2003:040</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:summary>The "screen dump" feature in Eterm 0.9.1 and earlier allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0022">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.1" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.2" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.3" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.4" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.5" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.6" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.7" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.8" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:rxvt:rxvt:2.7.5</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.6.2</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.7.6</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.6.3</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.7.7</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.6.4</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.7.8</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.6.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0022</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:23.807-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11413.php">terminal-emulator-screen-dump(11413)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6938">6938</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-055.html">RHSA-2003:055</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-054.html">RHSA-2003:054</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:034">MDKSA-2003:034</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:summary>The "screen dump" feature in rxvt 2.7.8 allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0023">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.1" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.2" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.3" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.4" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.5" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.6" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.7" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.8" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:rxvt:rxvt:2.7.5</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.6.2</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.7.6</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.6.3</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.7.7</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.6.4</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.7.8</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.6.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0023</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:23.867-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11416.php">terminal-emulator-menu-modification(11416)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6947">6947</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-055.html">RHSA-2003:055</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-054.html">RHSA-2003:054</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:034">MDKSA-2003:034</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:summary>The menuBar feature in rxvt 2.7.8 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0024">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:aterm:aterm:0.42" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:aterm:aterm:0.42</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0024</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:23.947-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11416.php">terminal-emulator-menu-modification(11416)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6949">6949</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:summary>The menuBar feature in aterm 0.42 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0068">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:michael_jennings:eterm:0.8.10" />
                <cpe-lang:fact-ref name="cpe:/a:michael_jennings:eterm:0.9.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:michael_jennings:eterm:0.8.10</vuln:product>
            <vuln:product>cpe:/a:michael_jennings:eterm:0.9.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0068</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:17:47.647-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11414.php">terminal-emulator-window-title(11414)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/10237">10237</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:040">MDKSA-2003:040</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-496">DSA-496</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:summary>The Eterm terminal emulator 0.9.1 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0070">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:gnome:gnome-terminal:2.1" />
                <cpe-lang:fact-ref name="cpe:/a:gnome:gnome-terminal:2.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:gnome:gnome-terminal:2.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:gnome:gnome-terminal:2.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:gnome:gnome-terminal:2.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:gnome:gnome-terminal:2.2" />
                <cpe-lang:fact-ref name="cpe:/a:gnome:gnome-terminal:2.2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:gnome:gnome-terminal:2.1</vuln:product>
            <vuln:product>cpe:/a:gnome:gnome-terminal:2.2</vuln:product>
            <vuln:product>cpe:/a:gnome:gnome-terminal:2.2.1</vuln:product>
            <vuln:product>cpe:/a:gnome:gnome-terminal:2.1.1</vuln:product>
            <vuln:product>cpe:/a:gnome:gnome-terminal:2.1.2</vuln:product>
            <vuln:product>cpe:/a:gnome:gnome-terminal:2.1.3</vuln:product>
            <vuln:product>cpe:/a:gnome:gnome-terminal:2.1.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0070</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:17:47.913-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11414.php">terminal-emulator-window-title(11414)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-053.html">RHSA-2003:053</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://seclists.org/lists/bugtraq/2003/Mar/0010.html">GLSA-200303-2</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:summary>VTE, as used by default in gnome-terminal terminal emulator 2.2 and as an option in gnome-terminal 2.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0071">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.0" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.0.1</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.0</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.0</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.0.3</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0071</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:44.180-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11415.php">terminal-emulator-dec-udk(11415)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6950">6950</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-067.html">RHSA-2003:067</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-066.html">RHSA-2003:066</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-065.html">RHSA-2003:065</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-064.html">RHSA-2003:064</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-380">DSA-380</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:summary>The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0078">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.1c" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.2b" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.3" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.4" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5a" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6b" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6c" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6d" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6e" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6g" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6h" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta1" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta2" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.2" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8:pre-release" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.1" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:openssl:openssl:0.9.3</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.4</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.5</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6a</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6b</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6c</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.1c</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6d</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6e</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6g</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6h</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.0</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.2</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.3</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.7</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.6</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.5</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.4</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.2b</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.5a</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta2</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta3</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:4.8:pre-release</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:3.2</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:3.1</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0078</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:47.117-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openssl.org/news/secadv_20030219.txt">http://www.openssl.org/news/secadv_20030219.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104568426824439&amp;w=2">20030219 [OpenPKG-SA-2003.013] OpenPKG Security Advisory (openssl)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11369.php">ssl-cbc-information-leak(11369)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-253">DSA-253</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2003/0005">2003-0005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6884">6884</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-205.html">RHSA-2003:205</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-104.html">RHSA-2003:104</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-082.html">RHSA-2003:082</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-063.html">RHSA-2003:063</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-062.html">RHSA-2003:062</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3945">3945</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:020">MDKSA-2003:020</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>ENGARDE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.linuxsecurity.com/advisories/engarde_advisory-2874.html">ESA-20030220-005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/n-051.shtml">N-051</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104577183206905&amp;w=2">GLSA-200302-10</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104567627211904&amp;w=2">20030219 OpenSSL 0.9.7a and 0.9.6i released</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000570">CLSA-2003:570</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I">20030501-01-I</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>NETBSD</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.asc">NetBSD-SA2003-001</vuln:reference>
        </vuln:references>
        <vuln:summary>ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack."</vuln:summary>
    </entry>
    <entry id="CVE-2003-0079">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:hanterm:hanterm-xf:2.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:hanterm:hanterm-xf:2.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0079</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:47.197-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11415.php">terminal-emulator-dec-udk(11415)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6944">6944</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-071.html">RHSA-2003:071</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-070.html">RHSA-2003:070</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/4918">4918</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:summary>The DEC UDK processing feature in the hanterm (hanterm-xf) terminal emulator before 2.0.5 allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0063">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.0" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.0.1</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.0</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.0</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.0.3</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0063</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:42.460-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11414.php">terminal-emulator-window-title(11414)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6940">6940</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-067.html">RHSA-2003:067</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-066.html">RHSA-2003:066</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-065.html">RHSA-2003:065</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-064.html">RHSA-2003:064</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-380">DSA-380</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:summary>The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0064">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10f" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10m" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11f" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11m" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12f" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12m" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13f" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13m" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14f" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14m" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15f" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15m" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16f" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16m" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2f" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2m" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3f" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3m" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4f" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4m" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5f" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5m" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6f" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6m" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7f" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7m" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8f" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8m" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9f" />
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9m" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.26" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.30" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.34" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.04" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.20" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.22" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.1" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.2" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.3" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.1" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.14f</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.10f</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.5f</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.9m</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.10m</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.4m</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.9f</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.14m</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.15f</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.11f</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.0</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.4f</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:11.04</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.17</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:11.22</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.26</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.18</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:11.20</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.7m</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.3m</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.8m</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.11m</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.16</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.15</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.3.3</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.3.2</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.8f</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.3.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.15m</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.16m</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.12f</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.34</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.6m</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:10.30</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.3f</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.7f</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.2m</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.16f</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.12m</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:7.0</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.0.1</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:5.1</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.13f</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.5m</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.2f</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:4.3</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.6f</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.13m</vuln:product>
            <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0064</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:42.523-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11414.php">terminal-emulator-window-title(11414)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6942">6942</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/advisories/6236">HPSBUX0401-309</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:summary>The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0065">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:national_university_of_singapore:uxterm:2.3" />
                <cpe-lang:fact-ref name="cpe:/a:national_university_of_singapore:uxterm:2.4.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:national_university_of_singapore:uxterm:2.3</vuln:product>
            <vuln:product>cpe:/a:national_university_of_singapore:uxterm:2.4.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0065</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:42.603-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11414.php">terminal-emulator-window-title(11414)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6945">6945</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:summary>The uxterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0066">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.1" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.2" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.3" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.4" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.5" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.6" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.7" />
                <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.8" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:rxvt:rxvt:2.7.5</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.6.2</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.7.6</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.6.3</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.7.7</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.6.4</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.7.8</vuln:product>
            <vuln:product>cpe:/a:rxvt:rxvt:2.6.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0066</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:42.680-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11414.php">terminal-emulator-window-title(11414)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6953">6953</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/advisories/5137">200303-16</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-055.html">RHSA-2003:055</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-054.html">RHSA-2003:054</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:003">MDKSA-2003:003</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:summary>The rxvt terminal emulator 2.7.8 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0049">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0049</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:26.757-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11333.php">macos-afp-unauthorized-access(11333)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6860">6860</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1006107">1006107</vuln:reference>
        </vuln:references>
        <vuln:summary>Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0093">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.4" />
                <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.4a6" />
                <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.5" />
                <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.6.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:lbl:tcpdump:3.6.2</vuln:product>
            <vuln:product>cpe:/a:lbl:tcpdump:3.4a6</vuln:product>
            <vuln:product>cpe:/a:lbl:tcpdump:3.5.2</vuln:product>
            <vuln:product>cpe:/a:lbl:tcpdump:3.4</vuln:product>
            <vuln:product>cpe:/a:lbl:tcpdump:3.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0093</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:17:54.197-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=81585">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=81585</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11324">tcpdump-radius-decoder-dos(11324)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-214.html">RHSA-2003:214</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-033.html">RHSA-2003:033</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-032.html">RHSA-2003:032</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027">MDKSA-2003:027</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-261">DSA-261</vuln:reference>
        </vuln:references>
        <vuln:summary>The RADIUS decoder in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service (crash) via an invalid RADIUS packet with a header length field of 0, which causes tcpdump to generate data within an infinite loop.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0094">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:util-linux:2.11n" />
                <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:util-linux:2.11u" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:andries_brouwer:util-linux:2.11u</vuln:product>
            <vuln:product>cpe:/a:andries_brouwer:util-linux:2.11n</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0094</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:48.727-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11318">utillinux-mcookie-cookie-predictable(11318)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6855">6855</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:016">MDKSA-2003:016</vuln:reference>
        </vuln:references>
        <vuln:summary>A patch for mcookie in the util-linux package for Mandrake Linux 8.2 and 9.0 uses /dev/urandom instead of /dev/random, which causes mcookie to use an entropy source that is more predictable than expected, which may make it easier for certain types of attacks to succeed.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0095">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.7" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.7.1" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:oracle:oracle9i:9.0.2</vuln:product>
            <vuln:product>cpe:/a:oracle:oracle9i:9.0</vuln:product>
            <vuln:product>cpe:/a:oracle:oracle9i:9.0.1</vuln:product>
            <vuln:product>cpe:/a:oracle:database_server:9.2.1</vuln:product>
            <vuln:product>cpe:/a:oracle:database_server:9.2.2</vuln:product>
            <vuln:product>cpe:/a:oracle:oracle8i:8.1.7</vuln:product>
            <vuln:product>cpe:/a:oracle:database_server:8.0.6</vuln:product>
            <vuln:product>cpe:/a:oracle:oracle9i:9.0.1.3</vuln:product>
            <vuln:product>cpe:/a:oracle:oracle8i:8.1.7.1</vuln:product>
            <vuln:product>cpe:/a:oracle:oracle9i:9.0.1.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0095</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/953746">VU#953746</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-2003-05.html">CA-2003-05</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://otn.oracle.com/deploy/security/pdf/2003alert51.pdf">http://otn.oracle.com/deploy/security/pdf/2003alert51.pdf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6849">6849</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/6319">6319</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11328.php">oracle-username-bo(11328)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/n-046.shtml">N-046</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104549693426042&amp;w=2">20030217 Oracle unauthenticated remote system compromise (#NISR16022003a)</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable through client applications that perform their own authentication, as demonstrated using LOADPSP.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0096">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.7" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.7.1" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:oracle:oracle9i:9.0.2</vuln:product>
            <vuln:product>cpe:/a:oracle:oracle9i:9.0</vuln:product>
            <vuln:product>cpe:/a:oracle:oracle9i:9.0.1</vuln:product>
            <vuln:product>cpe:/a:oracle:database_server:9.2.1</vuln:product>
            <vuln:product>cpe:/a:oracle:database_server:9.2.2</vuln:product>
            <vuln:product>cpe:/a:oracle:oracle8i:8.1.7</vuln:product>
            <vuln:product>cpe:/a:oracle:database_server:8.0.6</vuln:product>
            <vuln:product>cpe:/a:oracle:oracle9i:9.0.1.3</vuln:product>
            <vuln:product>cpe:/a:oracle:oracle8i:8.1.7.1</vuln:product>
            <vuln:product>cpe:/a:oracle:oracle9i:9.0.1.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0096</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/840666">VU#840666</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/743954">VU#743954</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/663786">VU#663786</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-2003-05.html">CA-2003-05</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6850">6850</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6848">6848</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6847">6847</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.nextgenss.com/advisories/ora-tzofstbo.txt">http://www.nextgenss.com/advisories/ora-tzofstbo.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.nextgenss.com/advisories/ora-tmstmpbo.txt">http://www.nextgenss.com/advisories/ora-tmstmpbo.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.nextgenss.com/advisories/ora-bfilebo.txt">http://www.nextgenss.com/advisories/ora-bfilebo.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11327.php">oracle-totimestamptz-bo(11327)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11326.php">oracle-tzoffset-bo(11326)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11325.php">oracle-bfilename-directory-bo(11325)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/n-046.shtml">N-046</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://otn.oracle.com/deploy/security/pdf/2003alert50.pdf">http://otn.oracle.com/deploy/security/pdf/2003alert50.pdf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://otn.oracle.com/deploy/security/pdf/2003alert49.pdf">http://otn.oracle.com/deploy/security/pdf/2003alert49.pdf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://otn.oracle.com/deploy/security/pdf/2003alert48.pdf">http://otn.oracle.com/deploy/security/pdf/2003alert48.pdf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550346303295&amp;w=2">20030217 Oracle bfilename function buffer overflow vulnerability (#NISR16022003e)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104549782327321&amp;w=2">20030217 Oracle TZ_OFFSET Remote System Buffer Overrun (#NISR16022003c)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104549743326864&amp;w=2">20030217 Oracle TO_TIMESTAMP_TZ Remote System Buffer Overrun (#NISR16022003b)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0083.html">20030217 Oracle bfilename function buffer overflow vulnerability (#NISR16022003e)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0075.html">20030217 Oracle TZ_OFFSET Remote System Buffer Overrun (#NISR16022003c)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0073.html">20030217 Oracle unauthenticated remote system compromise (#NISR16022003a)</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTAMP_TZ function, (2) a long time zone argument to the TZ_OFFSET function, or (3) a long DIRECTORY parameter to the BFILENAME function.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0097">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:php:php:4.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0097</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:49.057-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104567042700840&amp;w=2">GLSA-200302-09</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550977011668&amp;w=2">20030217 PHP Security Advisory: CGI vulnerability in PHP version 4.3.0</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.slackware.com/changelog/current.php?cpu=i386">http://www.slackware.com/changelog/current.php?cpu=i386</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11343.php">php-cgi-sapi-access(11343)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6875">6875</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104567137502557&amp;w=2">GLSA-200302-09.1</vuln:reference>
        </vuln:references>
        <vuln:summary>Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).</vuln:summary>
    </entry>
    <entry id="CVE-2003-0098">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apc:apcupsd:3.10.4" />
                <cpe-lang:fact-ref name="cpe:/a:apc:apcupsd:3.8.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apc:apcupsd:3.10.4</vuln:product>
            <vuln:product>cpe:/a:apc:apcupsd:3.8.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0098</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:17:55.897-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-277">DSA-277</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/7200">7200</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2003_022_apcupsd.html">SuSE-SA:2003:022</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11334.php">apcupsd-logevent-format-string(11334)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/project/shownotes.php?release_id=137900">http://sourceforge.net/project/shownotes.php?release_id=137900</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1006108">1006108</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://hsj.shadowpenguin.org/misc/apcupsd_exp.txt">http://hsj.shadowpenguin.org/misc/apcupsd_exp.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/apcupsd/apcupsd/src/apcnisd.c.diff?r1=1.5&amp;r2=1.6">http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/apcupsd/apcupsd/src/apcnisd.c.diff?r1=1.5&amp;r2=1.6</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CALDERA</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-015.0.txt">CSSA-2003-015.0</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6828">6828</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:018">MDKSA-2003:018</vuln:reference>
        </vuln:references>
        <vuln:summary>Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0099">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apc:apcupsd:3.8.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apc:apcupsd:3.8.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0099</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:17:55.960-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-277">DSA-277</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/7200">7200</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11491.php">apcupsd-vsprintf-multiple-bo(11491)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/project/shownotes.php?release_id=137900">http://sourceforge.net/project/shownotes.php?release_id=137900</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/project/shownotes.php?release_id=137892">http://sourceforge.net/project/shownotes.php?release_id=137892</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2003_022_apcupsd.html">SuSE-SA:2003:022</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:018">MDKSA-2003:018</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1006108">1006108</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CALDERA</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-015.0.txt">CSSA-2003-015.0</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arbitrary code, related to usage of the vsprintf function.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0100">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2813%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2813%29aa" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2813%29ca" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2813%29ia" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2815%29aa" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2815%29ca" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2815%29ia" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2816%29aa" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2816%29ia" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2817%29cc" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2817%29ct" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2820%29aa4" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2824a%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2824b%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2828a%29ct" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2828a%29ia" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2836%29ca2" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2836%29cc2" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2836%29cc4" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%287%29aa" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%287%29ca" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%289%29ia" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1aa" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1ca" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1cc" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1ct" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1ia" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2810%29bc" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2811b%29t2" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2817%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2819%29gs0.2" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2819a%29gs6" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2823a%29bc1" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2826%29p2" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2826a%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2826b%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%284%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%284%29f" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%284%29f1" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%284%29xa" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%284%29xaf" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%288%29p" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%288%29sa1" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%288%29sa3" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%288%29sa5" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%288.9%29sa6" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%289%29p" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%289%29xa" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2bc" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2f" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2gs" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2p" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2sa" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2wa3" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2wa4" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2xa" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%281%29ed" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%281%29t" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%2811%29b" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%2811b%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%2811b%29t2" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%2811c%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%282%29xa" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%287%29db1" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%288%29db2" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3aa" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3da" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3db" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3ha" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3ma" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3na" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3t" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3wa4" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3xa" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29w" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29xa3" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29xb" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29xe" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2810%29s7" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2810%29w5" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2810%29w5%2818f%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2810%29w5%2818g%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2810a%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2811%29s6" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2811%29st4" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2811a%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2812%29s3" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2812a%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2813%29s6" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2813%29w5%2819c%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2813%29wt6%281%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2813a%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2814%29s7" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2814%29st" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2814%29st3" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2814%29w5%2820%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2814a%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2815%29s3" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2815%29s6" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2815a%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816%29s8" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816%29sc3" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816%29st1" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816%29w5%2821%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816.06%29s" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816a%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29s" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29s4" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29sl2" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29sl6" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29st1" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29st5" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817a%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2818%29s" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2818%29s5" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2818%29st1" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2818%29w5%2822b%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2818b%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xc" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xd" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xe" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xf" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xg" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282b%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%283%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%283%29t2" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%283d%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%284%29s" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%284%29t" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%284%29xe" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%284%29xe1" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%284%29xm" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%284%29xm1" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29t" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29t1" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29wc" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29wc2" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29wc2b" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29wc3" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29wc3b" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29wx" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xe" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xk" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xk2" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xn" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xn1" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xs" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xu" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29yb4" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285.1%29xp" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285.2%29xu" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285.3%29wc1" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285.4%29wc1" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%286b%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29db2" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29dc1" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29s1" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29sc" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29t" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29t2" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29wx5%2815a%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xe" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xe2" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xf" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xf1" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xk" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xk3" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xv" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287.4%29s" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287a%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%288%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%288%29s1" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%288.0.2%29s" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%288.3%29sc" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%288a%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%289%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%289%29s" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%289%29s8" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%289a%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0da" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0db" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0dc" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0s" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sc" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sl" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sp" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0st" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sx" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0t" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0w5" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0wc" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0wt" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0wx" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xa" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xb" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xc" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xd" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xe" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xf" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xg" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xh" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xi" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xj" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xk" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xl" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xm" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xn" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xp" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xq" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xr" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xs" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xu" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xv" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xw" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:cisco:ios:12.0%2818%29s5</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%287%29t</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2816%29w5%2821%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%2816%29ia</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2814%29w5%2820%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.3%287%29db1</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%283d%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.3da</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.3db</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%2823a%29bc1</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%285%29wc</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%288%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%285%29xk</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%287%29db2</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%285%29wc2b</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%285%29xn</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%285%29xs</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2810a%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2810%29w5%2818f%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%286b%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%285%29xu</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%285%29wx</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%284%29xm1</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%289%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2817%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%287a%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%285%29xe</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%285%29wc3b</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2f</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.3wa4</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1ia</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2816%29sc3</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2p</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%282b%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2814a%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.3%2811%29b</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%2813%29ia</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%282%29xf</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%282%29xg</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%2836%29ca2</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%284%29f1</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2816%29st1</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%282%29xc</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%282%29xe</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.3aa</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%282%29xd</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2wa4</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.3t</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2818%29s</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2wa3</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.3xa</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2gs</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%287%29ca</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0wt</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%2820%29aa4</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%2815%29ca</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%283%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0wx</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.3%281%29ed</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xa</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xb</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.3ha</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xc</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xd</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xe</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xf</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xg</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xh</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xi</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xj</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xk</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xl</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2811%29st4</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xm</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xn</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xr</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xq</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xp</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2813%29w5%2819c%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%281%29xa3</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xv</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xu</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2xa</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%285.1%29xp</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xs</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0xw</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%285.2%29xu</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%2828a%29ia</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2812%29s3</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2817%29st5</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2817%29st1</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%289%29p</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%287%29xe2</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.3%2811c%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%2813%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%281%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%288.9%29sa6</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%2815%29aa</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%288%29sa1</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%288%29sa3</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%289%29xa</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%288%29sa5</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%285.4%29wc1</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%285.3%29wc1</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%287%29xf1</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%281%29xe</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%287.4%29s</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%282%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%289%29ia</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%281%29xb</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.3%2811b%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%288.3%29sc</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.3%2811b%29t2</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2817%29s</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1ca</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%284%29xm</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%289a%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%288a%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.3%282%29xa</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1cc</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0st</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.3ma</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0sx</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0dc</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0sl</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0da</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0db</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0sp</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%284%29xe</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1ct</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%285%29wc2</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2814%29st3</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%285%29wc3</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%284%29xaf</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2814%29st</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%289%29s</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%2828a%29ct</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%289%29s8</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2813%29s6</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%281%29w</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1aa</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%284%29xa</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%284%29s</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2817%29s4</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2812a%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0w5</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%288%29s1</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2810%29w5</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%285%29yb4</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%287%29xv</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0wc</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2816a%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2818%29st1</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2814%29s7</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%287%29xk</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%2813%29aa</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%2817%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%284%29t</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%287%29xf</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%287%29xe</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%287%29aa</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2816.06%29s</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%285%29t</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%2826%29p2</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%2826a%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.3%281%29t</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%2817%29ct</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%285%29t1</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%287%29wx5%2815a%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%287%29s1</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%2819a%29gs6</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%287%29xk3</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%284%29f</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%2836%29cc4</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%2824a%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%2817%29cc</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%2836%29cc2</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%285%29xn1</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2818b%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2815%29s3</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%287%29t2</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2815%29s6</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%2813%29ca</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%2824b%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%2810%29bc</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%288%29p</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%283%29t2</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2810%29w5%2818g%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%2815%29ia</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1%2816%29aa</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2813a%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%284%29xe1</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.1</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2810%29s7</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.3</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%284%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2816%29s8</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2811a%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2811%29s6</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0s</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0t</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2sa</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%287%29sc</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%287%29dc1</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.3%288%29db2</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%288.0.2%29s</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2815a%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2813%29wt6%281%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%2826b%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%2819%29gs0.2</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2bc</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0sc</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2818%29w5%2822b%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2817%29sl6</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2817a%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%2817%29sl2</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.3na</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.2%2811b%29t2</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0%285%29xk2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0100</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:49.507-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104587206702715&amp;w=2">20030221 Re: Cisco IOS OSPF exploit</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11373.php">cisco-ios-ospf-bo(11373)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104576100719090&amp;w=2">20030220 Cisco IOS OSPF exploit</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6895">6895</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a large number of OSPF neighbor announcements.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0101">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:engardelinux:guardian_digital_webtool:1.2" />
                <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.4" />
                <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.5" />
                <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.6" />
                <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.7" />
                <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.8" />
                <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.9" />
                <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.91" />
                <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.92" />
                <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.93" />
                <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.94" />
                <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.95" />
                <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.96" />
                <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.97" />
                <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.98" />
                <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.99" />
                <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.0.50" />
                <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.0.60" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:usermin:usermin:0.4</vuln:product>
            <vuln:product>cpe:/a:usermin:usermin:0.5</vuln:product>
            <vuln:product>cpe:/a:webmin:webmin:1.0.60</vuln:product>
            <vuln:product>cpe:/a:webmin:webmin:1.0.50</vuln:product>
            <vuln:product>cpe:/a:usermin:usermin:0.8</vuln:product>
            <vuln:product>cpe:/a:usermin:usermin:0.9</vuln:product>
            <vuln:product>cpe:/a:usermin:usermin:0.6</vuln:product>
            <vuln:product>cpe:/a:usermin:usermin:0.7</vuln:product>
            <vuln:product>cpe:/a:usermin:usermin:0.91</vuln:product>
            <vuln:product>cpe:/a:usermin:usermin:0.92</vuln:product>
            <vuln:product>cpe:/a:usermin:usermin:0.97</vuln:product>
            <vuln:product>cpe:/a:engardelinux:guardian_digital_webtool:1.2</vuln:product>
            <vuln:product>cpe:/a:usermin:usermin:0.98</vuln:product>
            <vuln:product>cpe:/a:usermin:usermin:0.99</vuln:product>
            <vuln:product>cpe:/a:usermin:usermin:0.93</vuln:product>
            <vuln:product>cpe:/a:usermin:usermin:0.94</vuln:product>
            <vuln:product>cpe:/a:usermin:usermin:0.95</vuln:product>
            <vuln:product>cpe:/a:usermin:usermin:0.96</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0101</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:49.570-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=webmin-announce&amp;m=104587858408101&amp;w=2">http://marc.theaimsgroup.com/?l=webmin-announce&amp;m=104587858408101&amp;w=2</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610300325629&amp;w=2">20030224 [SNS Advisory No.62] Webmin/Usermin Session ID Spoofing Vulnerability "Episode 2"</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6915">6915</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.lac.co.jp/security/english/snsadv_e/62_e.html">http://www.lac.co.jp/security/english/snsadv_e/62_e.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11390.php">webmin-usermin-root-access(11390)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-319">DSA-319</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/n-058.shtml">N-058</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610336226274&amp;w=2">20030224 GLSA:  usermin (200302-14)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610245624895&amp;w=2">20030224 Webmin 1.050 - 1.060 remote exploit</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>ENGARDE</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/linux/engarde/2003-q1/0008.html">ESA-20030225-006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/hp/2003-q1/0063.html">HPSBUX0303-250</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20030602-01-I">20030602-01-I</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1006160">1006160</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:025">MDKSA-2003:025</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.linuxsecurity.com/advisories/gentoo_advisory-2886.html">http://www.linuxsecurity.com/advisories/gentoo_advisory-2886.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/8163">8163</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/8115">8115</vuln:reference>
        </vuln:references>
        <vuln:summary>miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0087">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:national_language_support:libim" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:national_language_support:libim</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0087</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:47.993-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/advisory/02.12.03.txt">http://www.idefense.com/advisory/02.12.03.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11309">aix-aixterm-libim-bo(11309)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6840">6840</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/7996">7996</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40320&amp;apar=only">IY40320</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40317&amp;apar=only">IY40317</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40307&amp;apar=only">IY40307</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104508833214691&amp;w=2">20030212 libIM.a buffer overflow vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104508375107938&amp;w=2">20030212 iDEFENSE Security Advisory 02.12.03: Buffer Overflow in AIX libIM.a</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0066.html">20030212 iDEFENSE Security Advisory 02.12.03: Buffer Overflow in AIX libIM.a</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in libIM library (libIM.a) for National Language Support (NLS) on AIX 4.3 through 5.2 allows local users to gain privileges via several possible attack vectors, including a long -im argument to aixterm.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0088">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0088</vuln:cve-id>
        <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:48.070-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>ATSTAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.atstake.com/research/advisories/2003/a021403-1.txt">A021403-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11332.php">macos-trublueenvironment-gain-privileges(11332)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6859">6859</vuln:reference>
        </vuln:references>
        <vuln:summary>TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable that is used to write debugging information.</vuln:summary>
    </entry>
    <entry id="CVE-2003-1077">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-1077</vuln:cve-id>
        <vuln:published-datetime>2003-03-05T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:21:42.430-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-24T11:34:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-51300-1">51300</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/8234/">8234</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11481">solaris-ufs-logging-dos(11481)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1006233">1006233</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/7032">7032</vuln:reference>
        </vuln:references>
        <vuln:summary>Unknown vulnerability in UFS for Solaris 9 for SPARC, with logging enabled, allows local users to cause a denial of service (UFS file system hang).</vuln:summary>
    </entry>
    <entry id="CVE-2003-0103">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:nokia:6210_handset:5.27" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:nokia:6210_handset:5.27</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0103</vuln:cve-id>
        <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:29.380-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6952">6952</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11421.php">nokia-6210-vcard-dos(11421)</vuln:reference>
        </vuln:references>
        <vuln:summary>Format string vulnerability in Nokia 6210 handset allows remote attackers to cause a denial of service (crash, lockup, or restart) via a Multi-Part vCard with fields containing a large number of format string specifiers.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0107">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:gnu:zlib:1.1.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:gnu:zlib:1.1.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0107</vuln:cve-id>
        <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:50.163-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/142121">VU#142121</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11381.php">zlib-gzprintf-bo(11381)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://online.securityfocus.com/archive/1/312869">20030222 buffer overrun in zlib 1.1.4</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610337726297&amp;w=2">20030223 poc zlib sploit just for fun :)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/mhonarc/security-announce/msg00038.html">http://lists.apple.com/mhonarc/security-announce/msg00038.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6913">6913</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-081.html">RHSA-2003:081</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-079.html">RHSA-2003:079</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/6599">6599</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:033">MDKSA-2003:033</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F57405">57405</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887247624907&amp;w=2">GLSA-200303-25</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104620610427210&amp;w=2">20030225 [sorcerer-spells] ZLIB-SORCERER2003-02-25</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610536129508&amp;w=2">20030224 Re: buffer overrun in zlib 1.1.4</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com/atualizacoes/?id=a&amp;anuncio=000619">CLSA-2003:619</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>NETBSD</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-004.txt.asc">NetBSD-SA2003-004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CALDERA</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-011.0.txt">CSSA-2003-011.0</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denial of service or possibly execute arbitrary code.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0108">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.6.2" />
                <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.7" />
                <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.7.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:lbl:tcpdump:3.6.2</vuln:product>
            <vuln:product>cpe:/a:lbl:tcpdump:3.7</vuln:product>
            <vuln:product>cpe:/a:lbl:tcpdump:3.7.1</vuln:product>
            <vuln:product>cpe:/a:lbl:tcpdump:3.5.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0108</vuln:cve-id>
        <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:30.117-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6974">6974</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/advisory/02.27.03.txt">http://www.idefense.com/advisory/02.27.03.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-255">DSA-255</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11434.php">tcpdump-isakmp-dos(11434)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-214.html">RHSA-2003:214</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-085.html">RHSA-2003:085</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-032.html">RHSA-2003:032</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2003_015_tcpdump.html">SuSE-SA:2003:0015</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027">MDKSA-2003:027</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104678787109030&amp;w=2">20030304 [OpenPKG-SA-2003.014] OpenPKG Security Advisory (tcpdump)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104637420104189&amp;w=2">20030227 iDEFENSE Security Advisory 02.27.03: TCPDUMP Denial of Service Vulnerability in ISAKMP Packet Parsin</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000629">CLA-2003:629</vuln:reference>
        </vuln:references>
        <vuln:summary>isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed ISAKMP packet to UDP port 500, which causes tcpdump to enter an infinite loop.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0120">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mhc-utils:mhc-utils:0.25_snap2001-06-25" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mhc-utils:mhc-utils:0.25_snap2001-06-25</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0120</vuln:cve-id>
        <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:32.130-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>1.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-256">DSA-256</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6978">6978</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11439.php">mhc-adb2mhc-insecure-tmp(11439)</vuln:reference>
        </vuln:references>
        <vuln:summary>adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0050">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_streaming_server:4.1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apple:quicktime_streaming_server:4.1.1</vuln:product>
            <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0050</vuln:cve-id>
        <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:26.820-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11401.php">quicktime-darwin-command-execution(11401)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6954">6954</vuln:reference>
        </vuln:references>
        <vuln:summary>parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0051">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_streaming_server:4.1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apple:quicktime_streaming_server:4.1.1</vuln:product>
            <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0051</vuln:cve-id>
        <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:26.897-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11402.php">quicktime-darwin-path-disclosure(11402)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6956">6956</vuln:reference>
        </vuln:references>
        <vuln:summary>parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0052">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_streaming_server:4.1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apple:quicktime_streaming_server:4.1.1</vuln:product>
            <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0052</vuln:cve-id>
        <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:26.977-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11403.php">quicktime-darwin-directory-disclosure(11403)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6955">6955</vuln:reference>
        </vuln:references>
        <vuln:summary>parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0053">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_streaming_server:4.1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apple:quicktime_streaming_server:4.1.1</vuln:product>
            <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0053</vuln:cve-id>
        <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:27.040-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11404.php">quicktime-darwin-parsexml-xss(11404)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6958">6958</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0054">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_streaming_server:4.1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apple:quicktime_streaming_server:4.1.1</vuln:product>
            <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0054</vuln:cve-id>
        <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:27.117-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11405.php">quicktime-darwin-describe-xss(11405)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6960">6960</vuln:reference>
        </vuln:references>
        <vuln:summary>Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0055">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_darwin_mp3_broadcaster" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apple:quicktime_darwin_mp3_broadcaster</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0055</vuln:cve-id>
        <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T20:05:27.197-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11406.php">quicktime-darwin-mp3-bo(11406)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6957">6957</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long filename.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0009">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home" />
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
            <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0009</vuln:cve-id>
        <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:12.833-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/489721">VU#489721</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6966">6966</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MS</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.microsoft.com/technet/security/bulletin/ms03-006.asp">MS03-006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104636383018686&amp;w=2">20030227 MS-Windows ME IE/Outlook/HelpCenter critical vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11425.php">winme-hsc-hcp-bo(11425)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/6074">6074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/n-047.shtml">N-047</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious script in the topic parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0033">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.0" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.1" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.2" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.3" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.4" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.5" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.6" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.7" />
                <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.9.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:snort:snort:1.8.4</vuln:product>
            <vuln:product>cpe:/a:snort:snort:1.8.3</vuln:product>
            <vuln:product>cpe:/a:snort:snort:1.8.2</vuln:product>
            <vuln:product>cpe:/a:snort:snort:1.8.1</vuln:product>
            <vuln:product>cpe:/a:snort:snort:1.9.0</vuln:product>
            <vuln:product>cpe:/a:snort:snort:1.8.7</vuln:product>
            <vuln:product>cpe:/a:snort:snort:1.8.6</vuln:product>
            <vuln:product>cpe:/a:snort:snort:1.8.5</vuln:product>
            <vuln:product>cpe:/a:snort:snort:1.8.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0033</vuln:cve-id>
        <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:17.333-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/916785">VU#916785</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-2003-13.html">CA-2003-13</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/6963">6963</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/10956.php">snort-rpc-fragment-bo(10956)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>ISS</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21951">20030303 Snort RPC Preprocessing Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/4418">4418</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:029">MDKSA-2003:029</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>ENGARDE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.linuxsecurity.com/advisories/engarde_advisory-2944.html">ESA-20030307-007</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-297">DSA-297</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154530427824&amp;w=2">GLSA-200304-06</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104716001503409&amp;w=2">GLSA-200303-6.1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104673386226064&amp;w=2">20030303 Snort RPC Vulnerability (fwd)</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0020">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:http_server</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0020</vuln:cve-id>
        <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:14.803-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:4114" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4114" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:150" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:150" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:100109" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100109" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9930">9930</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11412.php">apache-esc-seq-injection(11412)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2004/0027">2004-0027</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2004/0017">2004-0017</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.529643">SSA:2004-133</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-244.html">RHSA-2003:244</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-243.html">RHSA-2003:243</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-139.html">RHSA-2003:139</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-104.html">RHSA-2003:104</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-083.html">RHSA-2003:083</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-082.html">RHSA-2003:082</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:050">MDKSA-2003:050</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1">57628</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1">101555</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200405-22.xml">GLSA-200405-22</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108731648532365&amp;w=2">SSRT4717</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108437852004207&amp;w=2">20040512 [OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2">APPLE-SA-2004-05-03</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:046">MDKSA-2004:046</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:summary>Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0067">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:aterm:aterm:0.42" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:aterm:aterm:0.42</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0067</vuln:cve-id>
        <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:22.943-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11414.php">terminal-emulator-window-title(11414)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:summary>The aterm terminal emulator 0.42 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0081">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.8.18" />
                <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.0" />
                <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.1" />
                <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.2" />
                <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.3" />
                <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.4" />
                <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.5" />
                <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.6" />
                <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.7" />
                <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.8" />
                <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.9</vuln:product>
            <vuln:product>cpe:/a:ethereal_group:ethereal:0.8.18</vuln:product>
            <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.0</vuln:product>
            <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.1</vuln:product>
            <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.2</vuln:product>
            <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.3</vuln:product>
            <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.4</vuln:product>
            <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.5</vuln:product>
            <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.6</vuln:product>
            <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.7</vuln:product>
            <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.8</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0081</vuln:cve-id>
        <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:25.287-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:54" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:54" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/7049">7049</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.guninski.com/etherre.html">http://www.guninski.com/etherre.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ethereal.com/appnotes/enpa-sa-00008.html">http://www.ethereal.com/appnotes/enpa-sa-00008.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2003/dsa-258">DSA-258</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11497">ethereal-socks-format-string(11497)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-077.html">RHSA-2003:077</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-076.html">RHSA-2003:076</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2003_019_ethereal.html">SuSE-SA:2003:019</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.linuxsecurity.com/advisories/gentoo_advisory-2949.html">GLSA-200303-10</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://seclists.org/lists/fulldisclosure/2003/Mar/0080.html">20030308 Ethereal format string bug, yet still ethereal much better than windows</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2003:051">MDKSA-2003:051</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000627">CLSA-2003:627</vuln:reference>
        </vuln:references>
        <vuln:summary>Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0069">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:putty:putty:0.53" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:putty:putty:0.53</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0069</vuln:cve-id>
        <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:23.240-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11414.php">terminal-emulator-window-title(11414)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/8347">8347</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:summary>The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0077">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:hanterm:hanterm-xf:2.0.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:hanterm:hanterm-xf:2.0.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0077</vuln:cve-id>
        <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:24.600-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/11414.php">terminal-emulator-window-title(11414)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-071.html">RHSA-2003:071</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-070.html">RHSA-2003:070</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/4917">4917</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</vuln:reference>
        </vuln:references>
        <vuln:summary>The hanterm (hanterm-xf) terminal emulator 2.0.5 and earlier, and possibly later versions, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0121">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.0" />
                <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.1" />
                <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.2" />
                <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:clearswift:mailsweeper:4.3</vuln:product>
            <vuln:product>cpe:/a:clearswift:mailsweeper:4.2</vuln:product>
            <vuln:product>cpe:/a:clearswift:mailsweeper:4.1</vuln:product>
            <vuln:product>cpe:/a:clearswift:mailsweeper:4.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0121</vuln:cve-id>
        <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:32.257-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/7044">7044</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104716030503607&amp;w=2">20030307 Corsaire Security Advisory - Clearswift MAILsweeper MIME attachment evasion issue</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/316311">20030326 RE: Corsaire Security Advisory - Clearswift MAILsweeper MIME attachment evasion issue</vuln:reference>
        </vuln:references>
        <vuln:summary>Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specify a MIME-Version header field, which is processed by some mail clients.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0122">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:4.6.1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:4.6.3" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:4.6.4" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.10" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.11" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.4::solaris" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.4a" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.5:::french" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.6a" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.7::solaris" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.7a" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.8:::french" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.8a" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.9a" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.10" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.11" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.9a" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:r5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.8</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.10</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.11</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.5</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.11</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.10</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.6</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.9a</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.9</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.3</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.6a</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.4a</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.8a</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.8:::french</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.7::solaris</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.3</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:4.6.4</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:4.6.3</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.5</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:4.6.1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.4</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.5:::french</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.4::solaris</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.7a</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes_client:r5</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.9a</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0122</vuln:cve-id>
        <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:32.410-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/433489">VU#433489</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-2003-11.html">CA-2003-11</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/7037">7037</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105101">http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105101</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104757319829443&amp;w=2">20030313 R7-0010: Buffer Overflow in Lotus Notes Protocol Authentication</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.rapid7.com/advisories/R7-0010.html">http://www.rapid7.com/advisories/R7-0010.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11526">lotus-nrpc-bo(11526)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/n-065.shtml">N-065</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0125.html">20030313 R7-0010: Buffer Overflow in Lotus Notes Protocol Authentication</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0123">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:4.6.1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:4.6.3" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:4.6.4" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.10" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.11" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.4::solaris" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.4a" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.5:::french" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.6a" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.7::solaris" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.7a" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.8:::french" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.8a" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.9a" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.10" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.11" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.9a" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:r5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.8</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.10</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.11</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.5</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.11</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.10</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.6</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.9a</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.9</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.3</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.6a</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.4a</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.8a</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.8:::french</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.7::solaris</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.3</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:4.6.4</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:4.6.3</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.5</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:4.6.1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.4</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.5:::french</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.4::solaris</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.7a</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_notes_client:r5</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:5.0.9a</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0123</vuln:cve-id>
        <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:32.600-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/411489">VU#411489</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-2003-11.html">CA-2003-11</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/7038">7038</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105060">http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105060</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104757545500368&amp;w=2">20030313 R7-0011: Lotus Notes/Domino Web Retriever HTTP Status Buffer Overflow</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.rapid7.com/advisories/R7-0011.html">http://www.rapid7.com/advisories/R7-0011.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11525">lotus-web-retriever-bo(11525)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/n-065.shtml">N-065</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0124">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:1.5h1" />
                <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:1.5i" />
                <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:1.5i2" />
                <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:1.5j" />
                <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:1.5k" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:andries_brouwer:man:1.5i2</vuln:product>
            <vuln:product>cpe:/a:andries_brouwer:man:1.5h1</vuln:product>
            <vuln:product>cpe:/a:andries_brouwer:man:1.5i</vuln:product>
            <vuln:product>cpe:/a:andries_brouwer:man:1.5j</vuln:product>
            <vuln:product>cpe:/a:andries_brouwer:man:1.5k</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0124</vuln:cve-id>
        <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:32.803-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/7066">7066</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104740927915154&amp;w=2">20030311 Vulnerability in man &lt; 1.5l</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11512">man-myxsprintf-code-execution(11512)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-134.html">RHSA-2003:134</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2003-133.html">RHSA-2003:133</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104802285112752&amp;w=2">GLSA-200303-13</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000620">CLSA-2003:620</vuln:reference>
        </vuln:references>
        <vuln:summary>man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes the my_xsprintf function to return a string with the value "unsafe," which is then executed as a program via a system call if it is in the search path of the user who runs man.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0125">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:multitech:routefinder_550_vpn:4.63" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:multitech:routefinder_550_vpn:4.63</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0125</vuln:cve-id>
        <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:32.957-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.krusesecurity.dk/advisories/routefind550bof.txt">http://www.krusesecurity.dk/advisories/routefind550bof.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.multitech.com/Routers/RF550VPN.TXT">ftp://ftp.multitech.com/Routers/RF550VPN.TXT</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/11514">routefinder-vpn-options-bo(11514)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/7067">7067</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a denial of service (reboot) and execute arbitrary code via a long GET /OPTIONS value.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0126">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:multitech:routefinder_550_vpn:4.64_beta" />
                <cpe-lang:fact-ref name="cpe:/h:multitech:routefinder_550_vpn:4.63" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:multitech:routefinder_550_vpn:4.63</vuln:product>
            <vuln:product>cpe:/h:multitech:routefinder_550_vpn:4.64_beta</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0126</vuln:cve-id>
        <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:33.083-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.krusesecurity.dk/advisories/routefind550bof.txt">http://www.krusesecurity.dk/advisories/routefind550bof.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>The web interface for SOHO Routefinder 550 firmware 4.63 and earlier, and possibly later versions, has a default "admin" account with a blank password, which could allow attackers on the LAN side to conduct unauthorized activities.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0104">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.10" />
                <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.11" />
                <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.12" />
                <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.13" />
                <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.14" />
                <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.15" />
                <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.16" />
                <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.17" />
                <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.18" />
                <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.40" />
                <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.41" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:peoplesoft:peopletools:8.10</vuln:product>
            <vuln:product>cpe:/a:peoplesoft:peopletools:8.11</vuln:product>
            <vuln:product>cpe:/a:peoplesoft:peopletools:8.12</vuln:product>
            <vuln:product>cpe:/a:peoplesoft:peopletools:8.13</vuln:product>
            <vuln:product>cpe:/a:peoplesoft:peopletools:8.14</vuln:product>
            <vuln:product>cpe:/a:peoplesoft:peopletools:8.15</vuln:product>
            <vuln:product>cpe:/a:peoplesoft:peopletools:8.16</vuln:product>
            <vuln:product>cpe:/a:peoplesoft:peopletools:8.17</vuln:product>
            <vuln:product>cpe:/a:peoplesoft:peopletools:8.40</vuln:product>
            <vuln:product>cpe:/a:peoplesoft:peopletools:8.18</vuln:product>
            <vuln:product>cpe:/a:peoplesoft:peopletools:8.41</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0104</vuln:cve-id>
        <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:33:29.537-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/7053">7053</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/10962.php">peoplesoft-schedulertransfer-create-files(10962)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>ISS</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21999">20030310 PeopleSoft PeopleTools Remote Command Execution Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory 