<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" xmlns:patch="http://scap.nist.gov/schema/patch/0.1" xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/0.1" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" nvd_xml_version="2.0" pub_date="2013-05-17T07:08:51" xsi:schemaLocation="http://scap.nist.gov/schema/patch/0.1 http://nvd.nist.gov/schema/patch_0.1.xsd http://scap.nist.gov/schema/scap-core/0.1 http://nvd.nist.gov/schema/scap-core_0.1.xsd http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
  <entry id="CVE-2003-0001">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0001</vuln:cve-id>
    <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:21.290-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2665" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2665" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/412115" xml:lang="en">VU#412115</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-025.html" xml:lang="en">RHSA-2003:025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf" xml:lang="en">http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a010603-1.txt" xml:lang="en">A010603-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104222046632243&amp;w=2" xml:lang="en">20030110 More information regarding Etherleak</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0016.html" xml:lang="en">20030110 More information regarding Etherleak</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/307564/30/26270/threaded" xml:lang="en">20030117 Re: More information regarding Etherleak</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/305335/30/26420/threaded" xml:lang="en">20030106 Etherleak: Ethernet frame padding information leakage (A010603-1)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-088.html" xml:lang="en">RHSA-2003:088</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/9962" xml:lang="en">9962</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/7996" xml:lang="en">7996</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2665" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2665" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0002">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:content_management_server:2001"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:content_management_server:2001:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:content_management_server:2001:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:content_management_server:2001</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0002</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:22.087-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms03-002.asp" xml:lang="en">MS03-002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10318.php" xml:lang="en">mcms-manuallogin-reasontxt-xss (10318)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=103417794800719&amp;w=2" xml:lang="en">20021007 CSS on Microsoft Content Management Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/5922" xml:lang="en">5922</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0003">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server:jp"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server:jp</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0003</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:22.163-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:103" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:103" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/610986" xml:lang="en">VU#610986</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-03.html" xml:lang="en">CA-2003-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms03-001.asp" xml:lang="en">MS03-001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11132" xml:lang="en">win-locator-bo(11132)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6666" xml:lang="en">6666</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104393588232166&amp;w=2" xml:lang="en">20030130 Microsoft RPC Locator Buffer Overflow Vulnerability (#NISR29012003)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104394414713415&amp;w=2" xml:lang="en">20030130 Microsoft RPC Locator Buffer Overflow Vulnerability (#NISR29012003)</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:103" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:103" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0004">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0004</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:22.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms03-005.asp" xml:lang="en">MS03-005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6778" xml:lang="en">6778</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11260.php" xml:lang="en">winxp-windows-redirector-bo(11260)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878038418534&amp;w=2" xml:lang="en">20030327 NSFOCUS SA2003-01: Microsoft Windows XP Redirector Local Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0154.html" xml:lang="en">20030327 NSFOCUS SA2003-01: Microsoft Windows XP Redirector Local Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the Windows Redirector function in Microsoft Windows XP allows local users to execute arbitrary code via a long parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0007">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:outlook:2002:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2002:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0007</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:22.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms03-003.asp" xml:lang="en">MS03-003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11133" xml:lang="en">outlook-v1-certificate-plaintext(11133)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6667" xml:lang="en">6667</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0009">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0009</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:12.833-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/489721" xml:lang="en">VU#489721</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6966" xml:lang="en">6966</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms03-006.asp" xml:lang="en">MS03-006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104636383018686&amp;w=2" xml:lang="en">20030227 MS-Windows ME IE/Outlook/HelpCenter critical vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11425.php" xml:lang="en">winme-hsc-hcp-bo(11425)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6074" xml:lang="en">6074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-047.shtml" xml:lang="en">N-047</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious script in the topic parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0010">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0010</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:22.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:795" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:795" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:794" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:794" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:200" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:200" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:134" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:134" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7146" xml:lang="en">7146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms03-008.asp" xml:lang="en">MS03-008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104812108307645&amp;w=2" xml:lang="en">20030319 iDEFENSE Security Advisory 03.19.03: Heap Overflow in Windows Script Engine</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0139.html" xml:lang="en">20030319 Windows Scripting Engine issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=26" xml:lang="en">20030319 Heap Overflow in Windows Script Engine</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:134" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:134" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:794" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:794" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:795" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:795" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:200" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:200" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0011">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:isa_server:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:isa_server:2000:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:isa_server:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:isa_server:2000:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0011</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:13.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7145" xml:lang="en">7145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms03-009.asp" xml:lang="en">MS03-009</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of incoming DNS request that is not properly handled.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0012">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0012</vuln:cve-id>
    <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:22.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104154319200399&amp;w=2" xml:lang="en">20030102 [BUGZILLA] Security Advisory - remote database password disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10971.php" xml:lang="en">bugzilla-mining-world-writable(10971)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6502" xml:lang="en">6502</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-012.html" xml:lang="en">RHSA-2003:012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-230" xml:lang="en">DSA-230</vuln:reference>
    </vuln:references>
    <vuln:summary>The data collection script for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 sets world-writable permissions for the data/mining directory when it runs, which allows local users to modify or delete the data.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0013">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0013</vuln:cve-id>
    <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:22.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-230" xml:lang="en">DSA-230</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104154319200399&amp;w=2" xml:lang="en">20030102 [BUGZILLA] Security Advisory - remote database password disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6501" xml:lang="en">6501</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6351" xml:lang="en">6351</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10970.php" xml:lang="en">bugzilla-htaccess-database-password(10970)</vuln:reference>
    </vuln:references>
    <vuln:summary>The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of the localconfig file that are made from editors such as vi and Emacs, which could allow remote attackers to obtain a database password by directly accessing the backup file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0014">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:bmv:bmv:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bmv:bmv:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0014</vuln:cve-id>
    <vuln:published-datetime>2003-01-11T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:13.773-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-25T12:12:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18823" xml:lang="en">bmv-symlink(18823)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://securityfocus.org/bid/12229" xml:lang="en">12229</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-633" xml:lang="en">DSA-633</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://packages.debian.org/changelogs/pool/main/b/bmv/bmv_1.2-14.2/changelog" xml:lang="en">http://packages.debian.org/changelogs/pool/main/b/bmv/bmv_1.2-14.2/changelog</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012847" xml:lang="en">1012847</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13796" xml:lang="en">13796</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13793" xml:lang="en">13793</vuln:reference>
    </vuln:references>
    <vuln:summary>gsinterf.c in bmv 1.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0015">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.10.7"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.10.8"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.1p1"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.11.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.10.8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.10.7</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.11.1p1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.11</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.11.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.11.1</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.11.3</vuln:product>
      <vuln:product>cpe:/a:cvs:cvs:1.11.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0015</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:22.960-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/650937" xml:lang="en">VU#650937</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-02.html" xml:lang="en">CA-2003-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security.e-matters.de/advisories/012003.html" xml:lang="en">http://security.e-matters.de/advisories/012003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2003-013.html" xml:lang="en">RHSA-2003:013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11108" xml:lang="en">cvs-doublefree-memory-corruption(11108)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6650" xml:lang="en">6650</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-012.html" xml:lang="en">RHSA-2003:012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:009" xml:lang="en">MDKSA-2003:009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-233" xml:lang="en">DSA-233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-032.shtml" xml:lang="en">N-032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104438807203491&amp;w=2" xml:lang="en">FreeBSD-SA-03:01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104428571204468&amp;w=2" xml:lang="en">20030202 Exploit for CVS double free() for Linux pserver</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104342550612736&amp;w=2" xml:lang="en">20030124 Test program for CVS double-free.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104333092200589&amp;w=2" xml:lang="en">20030122 [security@slackware.com: [slackware-security] New CVS packages available]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://ccvs.cvshome.org/servlets/NewsItemView?newsID=51&amp;JServSessionIdservlets=5of2iuhr14" xml:lang="en">http://ccvs.cvshome.org/servlets/NewsItemView?newsID=51&amp;JServSessionIdservlets=5of2iuhr14</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0028.html" xml:lang="en">20030120 Advisory 01/2003: CVS remote vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-prog commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0016">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0016</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:23.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/979793" xml:lang="en">VU#979793</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/825177" xml:lang="en">VU#825177</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2" xml:lang="en">[apache-httpd-announce] 20030120 [ANNOUNCE] Apache 2.0.44 Released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.apacheweek.com/issues/03-01-24#security" xml:lang="en">http://www.apacheweek.com/issues/03-01-24#security</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11125" xml:lang="en">apache-device-code-execution(11125)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11124" xml:lang="en">apache-device-name-dos(11124)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6659" xml:lang="en">6659</vuln:reference>
    </vuln:references>
    <vuln:summary>Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0017">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0017</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:23.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2" xml:lang="en">http://marc.theaimsgroup.com/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2</vuln:reference>
    </vuln:references>
    <vuln:summary>Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0018">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0018</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:23.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>3.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-025.html" xml:lang="en">RHSA-2003:025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-423" xml:lang="en">DSA-423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11249.php" xml:lang="en">linux-odirect-information-leak(11249)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6763" xml:lang="en">6763</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:014" xml:lang="en">MDKSA-2003:014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-358" xml:lang="en">DSA-358</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://linux.bkbits.net:8080/linux-2.4/cset@3e2f193drGJDBg9SG6JwaDQwCBnAMQ" xml:lang="en">http://linux.bkbits.net:8080/linux-2.4/cset@3e2f193drGJDBg9SG6JwaDQwCBnAMQ</vuln:reference>
    </vuln:references>
    <vuln:summary>Linux kernel 2.4.10 through 2.4.21-pre4 does not properly handle the O_DIRECT feature, which allows local attackers with write privileges to read portions of previously deleted files, or cause file system corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0019">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:linux:8.0::i386</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0019</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:23.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/134025" xml:lang="en">VU#134025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-056.html" xml:lang="en">RHSA-2003:056</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11276.php" xml:lang="en">linux-umlnet-gain-privileges(11276)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6801" xml:lang="en">6801</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-044.shtml" xml:lang="en">N-044</vuln:reference>
    </vuln:references>
    <vuln:summary>uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0020">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0020</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:14.803-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4114" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4114" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:150" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:150" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:100109" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100109" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9930" xml:lang="en">9930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11412.php" xml:lang="en">apache-esc-seq-injection(11412)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2004/0027" xml:lang="en">2004-0027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2004/0017" xml:lang="en">2004-0017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.529643" xml:lang="en">SSA:2004-133</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-244.html" xml:lang="en">RHSA-2003:244</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-243.html" xml:lang="en">RHSA-2003:243</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-139.html" xml:lang="en">RHSA-2003:139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-104.html" xml:lang="en">RHSA-2003:104</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-083.html" xml:lang="en">RHSA-2003:083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-082.html" xml:lang="en">RHSA-2003:082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:050" xml:lang="en">MDKSA-2003:050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1" xml:lang="en">57628</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1" xml:lang="en">101555</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200405-22.xml" xml:lang="en">GLSA-200405-22</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108731648532365&amp;w=2" xml:lang="en">SSRT4717</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108437852004207&amp;w=2" xml:lang="en">20040512 [OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2" xml:lang="en">APPLE-SA-2004-05-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:046" xml:lang="en">MDKSA-2004:046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:150" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:150" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4114" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4114" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:100109" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:100109" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0021">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:michael_jennings:eterm:0.8.10"/>
        <cpe-lang:fact-ref name="cpe:/a:michael_jennings:eterm:0.9.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:michael_jennings:eterm:0.8.10</vuln:product>
      <vuln:product>cpe:/a:michael_jennings:eterm:0.9.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0021</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:23.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11413.php" xml:lang="en">terminal-emulator-screen-dump(11413)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6936" xml:lang="en">6936</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:040" xml:lang="en">MDKSA-2003:040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:summary>The "screen dump" feature in Eterm 0.9.1 and earlier allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0022">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.8</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.5</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.2</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.6</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.3</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.1</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.7</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0022</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:23.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11413.php" xml:lang="en">terminal-emulator-screen-dump(11413)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6938" xml:lang="en">6938</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-055.html" xml:lang="en">RHSA-2003:055</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-054.html" xml:lang="en">RHSA-2003:054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:034" xml:lang="en">MDKSA-2003:034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:summary>The "screen dump" feature in rxvt 2.7.8 allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0023">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.8</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.5</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.2</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.6</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.3</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.1</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.7</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0023</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:23.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11416.php" xml:lang="en">terminal-emulator-menu-modification(11416)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6947" xml:lang="en">6947</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-055.html" xml:lang="en">RHSA-2003:055</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-054.html" xml:lang="en">RHSA-2003:054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:034" xml:lang="en">MDKSA-2003:034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:summary>The menuBar feature in rxvt 2.7.8 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0024">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:aterm:aterm:0.42"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aterm:aterm:0.42</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0024</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:23.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11416.php" xml:lang="en">terminal-emulator-menu-modification(11416)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6949" xml:lang="en">6949</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:summary>The menuBar feature in aterm 0.42 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0025">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:horde:imp:2.2.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:horde:imp:2.2.2</vuln:product>
      <vuln:product>cpe:/a:horde:imp:2.2.3</vuln:product>
      <vuln:product>cpe:/a:horde:imp:2.2.1</vuln:product>
      <vuln:product>cpe:/a:horde:imp:2.2.8</vuln:product>
      <vuln:product>cpe:/a:horde:imp:2.2.6</vuln:product>
      <vuln:product>cpe:/a:horde:imp:2.2.7</vuln:product>
      <vuln:product>cpe:/a:horde:imp:2.2</vuln:product>
      <vuln:product>cpe:/a:horde:imp:2.2.5</vuln:product>
      <vuln:product>cpe:/a:horde:imp:2.2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0025</vuln:cve-id>
    <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:24.023-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-229" xml:lang="en">DSA-229</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104204786206563&amp;w=2" xml:lang="en">20030108 IMP 2.x SQL injection vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005904" xml:lang="en">1005904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6559" xml:lang="en">6559</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/306268" xml:lang="en">20030108 Re: IMP 2.x SQL injection vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8177" xml:lang="en">8177</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8087" xml:lang="en">8087</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using mailbox.php3.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0026">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc7"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc6</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc3</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc5</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc8</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc4</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc7</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0026</vuln:cve-id>
    <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:11:57.250-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/284857" xml:lang="en">VU#284857</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-01.html" xml:lang="en">CA-2003-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-011.html" xml:lang="en">RHSA-2003:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-231" xml:lang="en">DSA-231</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.suse.com/de/security/2003_006_dhcp.html" xml:lang="en">SuSE-SA:2003:0006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11073" xml:lang="en">dhcpd-minires-multiple-bo(11073)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.suse.com/de/security/2003_006_dhcp.html" xml:lang="en">SuSE-SA:2003:0006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005924" xml:lang="en">1005924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6627" xml:lang="en">6627</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.002.html" xml:lang="en">OpenPKG-SA-2003.002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:007" xml:lang="en">MDKSA-2003:007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-031.shtml" xml:lang="en">N-031</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000562" xml:lang="en">CLA-2003:562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2003-01/0250.html" xml:lang="en">20030122 [securityslackware.com: [slackware-security] New DHCP packages available]</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple stack-based buffer overflows in the error handling routines of the minires library, as used in the NSUPDATE capability for ISC DHCPD 3.0 through 3.0.1RC10, allow remote attackers to execute arbitrary code via a DHCP message containing a long hostname.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0027">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0:x86_update_2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0:x86_update_2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0027</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:24.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2592" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2592" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:195" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:195" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:120" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:120" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/850785" xml:lang="en">VU#850785</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.entercept.com/news/uspr/01-22-03.asp" xml:lang="en">http://www.entercept.com/news/uspr/01-22-03.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11129" xml:lang="en">solaris-kcms-directory-traversal(11129)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6665" xml:lang="en">6665</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/50104" xml:lang="en">50104</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104326556329850&amp;w=2" xml:lang="en">20030122 Entercept Ricochet Advisory: Sun Solaris KCMS Library Service Daemon Arbitrary File Retrieval Vulner</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:195" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:195" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2592" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2592" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:120" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:120" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0028">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.0.4a"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.1.1a"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.2.2a"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.2.2b"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openafs:openafs:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9m"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:6.0e"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:8.3"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:9.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:9.0.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:9.2"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:9.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1.1:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.2:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.04"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.22"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux_series_700:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux_series_800:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.9"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openafs:openafs:1.1.1a</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.7</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4m</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.1.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:stable</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.4</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.2.5</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.0.4a</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.9</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.2.4</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1.1:stable</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6f</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3f</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12f</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.1.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.22</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:stable</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.3</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.2.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8f</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:stable</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.2:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:release</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15f</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:9.0</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.0.4</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.3.2</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.1.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.3</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.2.1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.3</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.6</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.1.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.2.2b</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:stable</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.1</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.3.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:release</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7f</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.2.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16f</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.8</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:9.0.2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10f</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.2.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.1</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.2.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:9.2</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.2.1</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.2.3</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1.1:release</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.04</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4:stable</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.20</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9m</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12m</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux_series_800:10.20</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:6.1</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2f</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:6.0e</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10m</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.3</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.2.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:8.3</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.2.2a</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2m</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.7</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:8.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14m</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:7.0</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.3.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13m</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux_series_700:10.20</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.0.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3m</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.2</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.2.2</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:6.0</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.3.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13f</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5m</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1.1</vuln:product>
      <vuln:product>cpe:/a:openafs:openafs:1.0.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3.3</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:9.2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0028</vuln:cve-id>
    <vuln:published-datetime>2003-03-25T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:11:57.423-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:230" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:230" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-10.html" xml:lang="en">CA-2003-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/516825" xml:lang="en">VU#516825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105362148313082&amp;w=2" xml:lang="en">20030522 [slackware-security]  glibc XDR overflow fix (SSA:2003-141-03)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-091.html" xml:lang="en">RHSA-2003:091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-089.html" xml:lang="en">RHSA-2003:089</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-052.html" xml:lang="en">RHSA-2003:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-051.html" xml:lang="en">RHSA-2003:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_027_glibc.html" xml:lang="en">SuSE-SA:2003:027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-3024.html" xml:lang="en">ESA-20030321-010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>EEYE</vuln:source>
      <vuln:reference href="http://www.eeye.com/html/Research/Advisories/AD20030318.html" xml:lang="en">AD20030318</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-282" xml:lang="en">DSA-282</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-272" xml:lang="en">DSA-272</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-266" xml:lang="en">DSA-266</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878237121402&amp;w=2" xml:lang="en">2003-0014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104860855114117&amp;w=2" xml:lang="en">20030325 GLSA:  glibc (200303-22)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104811415301340&amp;w=2" xml:lang="en">20030319 MITKRB5-SA-2003-003: faulty length checks in xdrmem_getbytes</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104810574423662&amp;w=2" xml:lang="en">20030319 EEYE: XDR Integer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0140.html" xml:lang="en">20030319 EEYE: XDR Integer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-008.txt.asc" xml:lang="en">NetBSD-SA2003-008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded" xml:lang="en">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/316931/30/25250/threaded" xml:lang="en">20030331 GLSA: dietlibc (200303-29)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/315638/30/25430/threaded" xml:lang="en">20030319 RE: EEYE: XDR Integer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:037" xml:lang="en">MDKSA-2003:037</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:230" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:230" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0030">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:protegrity:secure.data:2.2.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:protegrity:secure.data:2.2.3.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:protegrity:secure.data:2.2.3.8</vuln:product>
      <vuln:product>cpe:/a:protegrity:secure.data:2.2.3.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0030</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:16.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/247545" xml:lang="en">VU#247545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7085" xml:lang="en">7085</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7084" xml:lang="en">7084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7083" xml:lang="en">7083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104758650516677&amp;w=2" xml:lang="en">20030313 Protegrity buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8294" xml:lang="en">8294</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflows in protegrity.dll of Protegrity Secure.Data Extension Feature (SEF) before 2.2.3.9 allow attackers with SQL access to execute arbitrary code via the extended stored procedures (1) xp_pty_checkusers, (2) xp_pty_insert, or (3) xp_pty_select.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0031">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5.1_r4"/>
        <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5_.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5.2</vuln:product>
      <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5_.0</vuln:product>
      <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5.3</vuln:product>
      <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5.1_r4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0031</vuln:cve-id>
    <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:24.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-228" xml:lang="en">DSA-228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104162752401212&amp;w=2" xml:lang="en">20030103 Multiple libmcrypt vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006181" xml:lang="en">1006181</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6510" xml:lang="en">6510</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104188513728573&amp;w=2" xml:lang="en">20030105 GLSA:  libmcrypt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000567" xml:lang="en">CLA-2003:567</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in libmcrypt before 2.5.5 allow attackers to cause a denial of service (crash).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0032">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5.1_r4"/>
        <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mcrypt:libmcrypt:2.5_.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5.2</vuln:product>
      <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5_.0</vuln:product>
      <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5.3</vuln:product>
      <vuln:product>cpe:/a:mcrypt:libmcrypt:2.5.1_r4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0032</vuln:cve-id>
    <vuln:published-datetime>2003-01-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:24.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-228" xml:lang="en">DSA-228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104162752401212&amp;w=2" xml:lang="en">20030103 Multiple libmcrypt vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10988.php" xml:lang="en">libmcrypt-libtool-memory-leak(10988)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6512" xml:lang="en">6512</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104188513728573&amp;w=2" xml:lang="en">20030105 GLSA:  libmcrypt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000567" xml:lang="en">CLA-2003:567</vuln:reference>
    </vuln:references>
    <vuln:summary>Memory leak in libmcrypt before 2.5.5 allows attackers to cause a denial of service (memory exhaustion) via a large number of requests to the application, which causes libmcrypt to dynamically load algorithms via libtool.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0033">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.3"/>
        <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.6"/>
        <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.8.7"/>
        <cpe-lang:fact-ref name="cpe:/a:snort:snort:1.9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:snort:snort:1.8.3</vuln:product>
      <vuln:product>cpe:/a:snort:snort:1.9.0</vuln:product>
      <vuln:product>cpe:/a:snort:snort:1.8.6</vuln:product>
      <vuln:product>cpe:/a:snort:snort:1.8.5</vuln:product>
      <vuln:product>cpe:/a:snort:snort:1.8.1</vuln:product>
      <vuln:product>cpe:/a:snort:snort:1.8.2</vuln:product>
      <vuln:product>cpe:/a:snort:snort:1.8.4</vuln:product>
      <vuln:product>cpe:/a:snort:snort:1.8.7</vuln:product>
      <vuln:product>cpe:/a:snort:snort:1.8.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0033</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:17.333-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/916785" xml:lang="en">VU#916785</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-13.html" xml:lang="en">CA-2003-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6963" xml:lang="en">6963</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10956.php" xml:lang="en">snort-rpc-fragment-bo(10956)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21951" xml:lang="en">20030303 Snort RPC Preprocessing Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/4418" xml:lang="en">4418</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:029" xml:lang="en">MDKSA-2003:029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-2944.html" xml:lang="en">ESA-20030307-007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-297" xml:lang="en">DSA-297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154530427824&amp;w=2" xml:lang="en">GLSA-200304-06</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104716001503409&amp;w=2" xml:lang="en">GLSA-200303-6.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104673386226064&amp;w=2" xml:lang="en">20030303 Snort RPC Vulnerability (fwd)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0034">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:jean-jacques_sarton:mtink:0.9.32"/>
        <cpe-lang:fact-ref name="cpe:/a:jean-jacques_sarton:mtink:0.9.33"/>
        <cpe-lang:fact-ref name="cpe:/a:jean-jacques_sarton:mtink:0.9.52"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jean-jacques_sarton:mtink:0.9.52</vuln:product>
      <vuln:product>cpe:/a:jean-jacques_sarton:mtink:0.9.33</vuln:product>
      <vuln:product>cpe:/a:jean-jacques_sarton:mtink:0.9.32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0034</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:24.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/01.21.03.txt" xml:lang="en">http://www.idefense.com/advisory/01.21.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html" xml:lang="en">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005959" xml:lang="en">1005959</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6656" xml:lang="en">6656</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010" xml:lang="en">MDKSA-2003:010</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long HOME environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0035">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:robert_krawitz:escputil:1.15.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:robert_krawitz:escputil:1.15.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0035</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:25.023-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/01.21.03.txt" xml:lang="en">http://www.idefense.com/advisory/01.21.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html" xml:lang="en">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005959" xml:lang="en">1005959</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6658" xml:lang="en">6658</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/307608/30/26270/threaded" xml:lang="en">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010" xml:lang="en">MDKSA-2003:010</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in escputil, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long printer-name command line argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0036">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rildo_pragana:ml85p"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rildo_pragana:ml85p</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0036</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:26.397-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/01.21.03.txt" xml:lang="en">http://www.idefense.com/advisory/01.21.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html" xml:lang="en">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005959" xml:lang="en">1005959</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/307608/30/26270/threaded" xml:lang="en">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010" xml:lang="en">MDKSA-2003:010</vuln:reference>
    </vuln:references>
    <vuln:summary>ml85p, as included in the printer-drivers package for Mandrake Linux, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable filenames of the form "mlg85p%d".</vuln:summary>
  </entry>
  <entry id="CVE-2003-0037">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:noffle:noffle:1.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:noffle:noffle:1.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0037</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:25.163-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-244" xml:lang="en">DSA-244</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11181" xml:lang="en">noffle-multiple-bo(11181)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6695" xml:lang="en">6695</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/7955" xml:lang="en">7955</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflows in noffle news server 1.0.1 and earlier allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0038">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:mailman:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0038</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:18.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-436" xml:lang="en">DSA-436</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://telia.dl.sourceforge.net/sourceforge/mailman/xss-2.1.0-patch.txt" xml:lang="en">http://telia.dl.sourceforge.net/sourceforge/mailman/xss-2.1.0-patch.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104342745916111" xml:lang="en">20030124 Mailman: cross-site scripting bug</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11152" xml:lang="en">mailman-email-variable-xss(11152)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1005987" xml:lang="en">1005987</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6677" xml:lang="en">6677</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/9205" xml:lang="en">9205</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0039">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc10"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc7"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc8"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:dhcpd:3.0.1:rc9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc9</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc10</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc6</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc3</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc5</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc8</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc4</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc7</vuln:product>
      <vuln:product>cpe:/a:isc:dhcpd:3.0.1:rc2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0039</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:18.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/149953" xml:lang="en">VU#149953</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-245" xml:lang="en">DSA-245</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104310927813830&amp;w=2" xml:lang="en">20030115 DoS against DHCP infrastructure with isc dhcrelay</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11187" xml:lang="en">dhcp-dhcrelay-dos(11187)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6628" xml:lang="en">6628</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-034.html" xml:lang="en">RHSA-2003:034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.openpkg.org/security/OpenPKG-SA-2003.012-dhcpd.html" xml:lang="en">20030219 [OpenPKG-SA-2003.012] OpenPKG Security Advisory (dhcpd)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000616" xml:lang="en">CLSA-2003:616</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://cc.turbolinux.com/security/TLSA-2003-26.txt" xml:lang="en">TLSA-2003-26</vuln:reference>
    </vuln:references>
    <vuln:summary>ISC dhcrelay (dhcp-relay) 3.0rc9 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (packet storm) via a certain BOOTP packet that is forwarded to a broadcast MAC address, causing an infinite loop that is not restricted by a hop count.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0040">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:double_precision_incorporated:courier_mta:0.37.3"/>
        <cpe-lang:fact-ref name="cpe:/a:inter7:courier-imap:1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:double_precision_incorporated:courier_mta:0.37.3</vuln:product>
      <vuln:product>cpe:/a:inter7:courier-imap:1.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0040</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:18.427-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6738" xml:lang="en">6738</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-247" xml:lang="en">DSA-247</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11213" xml:lang="en">courierimap-authmysqllib-sql-injection(11213)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0041">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos_ftp_client"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:6.2::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.0::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.1::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2::ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.3::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:linux:8.0::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.3::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.2::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.2::ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:6.2::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.0::i386</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos_ftp_client</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.1::i386</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0041</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:27.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-020.html" xml:lang="en">RHSA-2003:020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0047.html" xml:lang="en">20030128 MIT Kerberos FTP client remote shell commands execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:021" xml:lang="en">MDKSA-2003:021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8114" xml:lang="en">8114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/7979" xml:lang="en">7979</vuln:reference>
    </vuln:references>
    <vuln:summary>Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0042">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:tomcat:3.2.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.0</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2.4</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.1.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0042</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:25.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-246" xml:lang="en">DSA-246</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104394568616290&amp;w=2" xml:lang="en">20030130 Apache Jakarta Tomcat 3 URL parsing vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" xml:lang="en">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/" xml:lang="en">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11194" xml:lang="en">tomcat-null-directory-listing(11194)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6721" xml:lang="en">6721</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/5111" xml:lang="en">HPSBUX0303-249</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-060.shtml" xml:lang="en">N-060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/7977" xml:lang="en">7977</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/7972" xml:lang="en">7972</vuln:reference>
    </vuln:references>
    <vuln:summary>Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0043">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:tomcat:3.2.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.0</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2.4</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.1.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0043</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:26.023-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11195" xml:lang="en">tomcat-webxml-read-files(11195)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" xml:lang="en">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/" xml:lang="en">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6722" xml:lang="en">6722</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/5111" xml:lang="en">HPSBUX0303-249</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-246" xml:lang="en">DSA-246</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-060.shtml" xml:lang="en">N-060</vuln:reference>
    </vuln:references>
    <vuln:summary>Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0044">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3.1a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:tomcat:3.2.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.0</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2.4</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.1.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.3.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.3.1a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0044</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:26.087-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-246" xml:lang="en">DSA-246</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/5111" xml:lang="en">HPSBUX0303-249</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" xml:lang="en">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/" xml:lang="en">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11196" xml:lang="en">tomcat-web-app-xss(11196)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6720" xml:lang="en">6720</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/9204" xml:lang="en">9204</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/9203" xml:lang="en">9203</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-060.shtml" xml:lang="en">N-060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/7972" xml:lang="en">7972</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0045">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:3.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:tomcat:3.2.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.0</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2.4</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.1.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.2</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:3.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0045</vuln:cve-id>
    <vuln:published-datetime>2003-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:19.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/12102" xml:lang="en">jakarta-tomcat-msdos-dos(12102)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" xml:lang="en">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0046">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:celestial_software:absolutetelnet:2.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:celestial_software:absolutetelnet:2.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0046</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:26.413-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/01.28.03.txt" xml:lang="en">http://www.idefense.com/advisory/01.28.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.celestialsoftware.net/telnet/beta_software.html" xml:lang="en">http://www.celestialsoftware.net/telnet/beta_software.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386492422014&amp;w=2" xml:lang="en">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006013" xml:lang="en">1006013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6725" xml:lang="en">6725</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/7686" xml:lang="en">7686</vuln:reference>
    </vuln:references>
    <vuln:summary>AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0047">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:van_dyke_technologies:securecrt:3.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:van_dyke_technologies:securecrt:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:van_dyke_technologies:securefx:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:van_dyke_technologies:securefx:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:van_dyke_technologies:entunnel:1.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:van_dyke_technologies:securecrt:3.4.7</vuln:product>
      <vuln:product>cpe:/a:van_dyke_technologies:entunnel:1.0.2</vuln:product>
      <vuln:product>cpe:/a:van_dyke_technologies:securecrt:4.0.2</vuln:product>
      <vuln:product>cpe:/a:van_dyke_technologies:securefx:2.1.2</vuln:product>
      <vuln:product>cpe:/a:van_dyke_technologies:securefx:2.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0047</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:26.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/01.28.03.txt" xml:lang="en">http://www.idefense.com/advisory/01.28.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386492422014&amp;w=2" xml:lang="en">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006012" xml:lang="en">1006012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006011" xml:lang="en">1006011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006010" xml:lang="en">1006010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6728" xml:lang="en">6728</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6727" xml:lang="en">6727</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6726" xml:lang="en">6726</vuln:reference>
    </vuln:references>
    <vuln:summary>SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0048">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:putty:putty:0.48"/>
        <cpe-lang:fact-ref name="cpe:/a:putty:putty:0.49"/>
        <cpe-lang:fact-ref name="cpe:/a:putty:putty:0.53"/>
        <cpe-lang:fact-ref name="cpe:/a:putty:putty:0.53b"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:putty:putty:0.49</vuln:product>
      <vuln:product>cpe:/a:putty:putty:0.48</vuln:product>
      <vuln:product>cpe:/a:putty:putty:0.53b</vuln:product>
      <vuln:product>cpe:/a:putty:putty:0.53</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0048</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:26.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/01.28.03.txt" xml:lang="en">http://www.idefense.com/advisory/01.28.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006014" xml:lang="en">1006014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6724" xml:lang="en">6724</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386492422014&amp;w=2" xml:lang="en">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</vuln:reference>
    </vuln:references>
    <vuln:summary>PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0049">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0049</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:26.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11333.php" xml:lang="en">macos-afp-unauthorized-access(11333)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" xml:lang="en">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6860" xml:lang="en">6860</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006107" xml:lang="en">1006107</vuln:reference>
    </vuln:references>
    <vuln:summary>Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0050">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_streaming_server:4.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime_streaming_server:4.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0050</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:26.820-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" xml:lang="en">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11401.php" xml:lang="en">quicktime-darwin-command-execution(11401)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" xml:lang="en">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6954" xml:lang="en">6954</vuln:reference>
    </vuln:references>
    <vuln:summary>parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0051">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_streaming_server:4.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime_streaming_server:4.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0051</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:26.897-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" xml:lang="en">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11402.php" xml:lang="en">quicktime-darwin-path-disclosure(11402)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" xml:lang="en">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6956" xml:lang="en">6956</vuln:reference>
    </vuln:references>
    <vuln:summary>parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0052">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_streaming_server:4.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime_streaming_server:4.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0052</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:26.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" xml:lang="en">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11403.php" xml:lang="en">quicktime-darwin-directory-disclosure(11403)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" xml:lang="en">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6955" xml:lang="en">6955</vuln:reference>
    </vuln:references>
    <vuln:summary>parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0053">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_streaming_server:4.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime_streaming_server:4.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0053</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:27.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" xml:lang="en">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11404.php" xml:lang="en">quicktime-darwin-parsexml-xss(11404)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" xml:lang="en">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6958" xml:lang="en">6958</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0054">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_streaming_server:4.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime_streaming_server:4.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0054</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:27.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" xml:lang="en">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11405.php" xml:lang="en">quicktime-darwin-describe-xss(11405)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" xml:lang="en">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6960" xml:lang="en">6960</vuln:reference>
    </vuln:references>
    <vuln:summary>Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0055">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_darwin_mp3_broadcaster"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime_darwin_mp3_broadcaster</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0055</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:27.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" xml:lang="en">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11406.php" xml:lang="en">quicktime-darwin-mp3-bo(11406)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" xml:lang="en">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6957" xml:lang="en">6957</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long filename.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0056">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:slocate:slocate:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:slocate:slocate:2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:slocate:slocate:2.5</vuln:product>
      <vuln:product>cpe:/a:slocate:slocate:2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0056</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:15:01.740-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11369" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11369" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-252" xml:lang="en">DSA-252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104428624705363&amp;w=2" xml:lang="en">20030202 GLSA:  slocate</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.usg.org.uk/advisories/2003.001.txt" xml:lang="en">http://www.usg.org.uk/advisories/2003.001.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://www.net-security.org/advisory.php?id=2010" xml:lang="en">CLA-2003:643</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:015" xml:lang="en">MDKSA-2003:015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8749" xml:lang="en">8749</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8236" xml:lang="en">8236</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8118/" xml:lang="en">8118</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8007" xml:lang="en">8007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/7982" xml:lang="en">7982</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/7947" xml:lang="en">7947</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10720" xml:lang="en">10720</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2004-041.html" xml:lang="en">RHSA-2004:041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104348607205691&amp;w=2" xml:lang="en">20030125 Re: [USG- SA- 2003.001] USG Security Advisory (slocate)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104342864418213&amp;w=2" xml:lang="en">20030124 [USG- SA- 2003.001] USG Security Advisory (slocate)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" xml:lang="en">20040202-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-009.0.txt" xml:lang="en">CSSA-2003-009.0</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11369" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11369" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or (2) -r command line argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0057">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.0b25"/>
        <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:hypermail:hypermail:2.1_.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hypermail:hypermail:2.1.5</vuln:product>
      <vuln:product>cpe:/a:hypermail:hypermail:2.1.2</vuln:product>
      <vuln:product>cpe:/a:hypermail:hypermail:2.1.1</vuln:product>
      <vuln:product>cpe:/a:hypermail:hypermail:2.1_.0</vuln:product>
      <vuln:product>cpe:/a:hypermail:hypermail:2.1.3</vuln:product>
      <vuln:product>cpe:/a:hypermail:hypermail:2.0b25</vuln:product>
      <vuln:product>cpe:/a:hypermail:hypermail:2.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0057</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:41.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104369136703903&amp;w=2" xml:lang="en">20030127 Hypermail buffer overflows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11158" xml:lang="en">hypermail-long-hostname-bo(11158)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11157" xml:lang="en">hypermail-mail-attachment-bo(11157)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6690" xml:lang="en">6690</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6689" xml:lang="en">6689</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-248" xml:lang="en">DSA-248</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8030" xml:lang="en">8030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0042.html" xml:lang="en">20030126 Hypermail buffer overflows</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Hypermail 2 before 2.1.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code (1) via a long attachment filename that is not properly handled by the hypermail executable, or (2) by connecting to the mail CGI program from an IP address that reverse-resolves to a long hostname.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0058">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:enterprise_authentication_mechanism:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.4</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
      <vuln:product>cpe:/a:sun:enterprise_authentication_mechanism:1.0</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0058</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:21.317-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1110" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1110" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/661243" xml:lang="en">VU#661243</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6683" xml:lang="en">6683</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt" xml:lang="en">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/10099" xml:lang="en">kerberos-kdc-null-pointer-dos(10099)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-168.html" xml:lang="en">RHSA-2003:168</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-052.html" xml:lang="en">RHSA-2003:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-051.html" xml:lang="en">RHSA-2003:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:043" xml:lang="en">MDKSA-2003:043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/50142" xml:lang="en">50142</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639" xml:lang="en">CLSA-2003:639</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1110" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1110" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0059">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0059</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:21.490-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/684563" xml:lang="en">VU#684563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6714" xml:lang="en">6714</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt" xml:lang="en">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11188" xml:lang="en">kerberos-kdc-user-spoofing(11188)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-168.html" xml:lang="en">RHSA-2003:168</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-052.html" xml:lang="en">RHSA-2003:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-051.html" xml:lang="en">RHSA-2003:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:043" xml:lang="en">MDKSA-2003:043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639" xml:lang="en">CLSA-2003:639</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0060">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.4</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.2</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0060</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:21.630-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/787523" xml:lang="en">VU#787523</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6712" xml:lang="en">6712</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt" xml:lang="en">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11189" xml:lang="en">kerberos-kdc-format-string(11189)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/4879" xml:lang="en">4879</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639" xml:lang="en">CLSA-2003:639</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0061">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0061</vuln:cve-id>
    <vuln:published-datetime>2002-01-11T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:21.787-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-25T11:27:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=87&amp;type=vulnerabilities&amp;flashstatus=true" xml:lang="en">20030203 HP UX passwd Binary Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0062">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:eset_software:nod32_antivirus:1.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:eset_software:nod32_antivirus:1.0.12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eset_software:nod32_antivirus:1.0.12</vuln:product>
      <vuln:product>cpe:/a:eset_software:nod32_antivirus:1.0.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0062</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:42.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/02.10.03.txt" xml:lang="en">http://www.idefense.com/advisory/02.10.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6803" xml:lang="en">6803</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11282.php" xml:lang="en">nod32-pathname-bo(11282)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104490777824360&amp;w=2" xml:lang="en">20030210 iDEFENSE Security Advisory 02.10.03: Buffer Overflow In NOD32 Antivirus Software for Unix</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Eset Software NOD32 for UNIX before 1.013 allows local users to execute arbitrary code via a long path name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0063">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.0.1</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.0.3</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0063</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:42.460-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11414.php" xml:lang="en">terminal-emulator-window-title(11414)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6940" xml:lang="en">6940</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-067.html" xml:lang="en">RHSA-2003:067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-066.html" xml:lang="en">RHSA-2003:066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-065.html" xml:lang="en">RHSA-2003:065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-064.html" xml:lang="en">RHSA-2003:064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-380" xml:lang="en">DSA-380</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:summary>The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0064">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9m"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.26"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.30"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.34"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.04"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.22"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4m</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.04</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.20</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9m</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.34</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.22</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8f</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.26</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15f</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.30</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3m</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13f</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0064</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:42.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11414.php" xml:lang="en">terminal-emulator-window-title(11414)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6942" xml:lang="en">6942</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/6236" xml:lang="en">HPSBUX0401-309</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:summary>The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0065">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:national_university_of_singapore:uxterm:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:national_university_of_singapore:uxterm:2.4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:national_university_of_singapore:uxterm:2.4.1</vuln:product>
      <vuln:product>cpe:/a:national_university_of_singapore:uxterm:2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0065</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:42.603-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11414.php" xml:lang="en">terminal-emulator-window-title(11414)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6945" xml:lang="en">6945</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:summary>The uxterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0066">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rxvt:rxvt:2.7.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.8</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.5</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.2</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.6</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.3</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.1</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.7.7</vuln:product>
      <vuln:product>cpe:/a:rxvt:rxvt:2.6.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0066</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:42.680-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11414.php" xml:lang="en">terminal-emulator-window-title(11414)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6953" xml:lang="en">6953</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/5137" xml:lang="en">200303-16</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-055.html" xml:lang="en">RHSA-2003:055</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-054.html" xml:lang="en">RHSA-2003:054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:003" xml:lang="en">MDKSA-2003:003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:summary>The rxvt terminal emulator 2.7.8 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0067">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:aterm:aterm:0.42"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aterm:aterm:0.42</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0067</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:22.943-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11414.php" xml:lang="en">terminal-emulator-window-title(11414)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:summary>The aterm terminal emulator 0.42 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0068">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:michael_jennings:eterm:0.8.10"/>
        <cpe-lang:fact-ref name="cpe:/a:michael_jennings:eterm:0.9.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:michael_jennings:eterm:0.8.10</vuln:product>
      <vuln:product>cpe:/a:michael_jennings:eterm:0.9.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0068</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:47.647-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11414.php" xml:lang="en">terminal-emulator-window-title(11414)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10237" xml:lang="en">10237</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:040" xml:lang="en">MDKSA-2003:040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-496" xml:lang="en">DSA-496</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:summary>The Eterm terminal emulator 0.9.1 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0069">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:putty:putty:0.53"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:putty:putty:0.53</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0069</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:23.240-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11414.php" xml:lang="en">terminal-emulator-window-title(11414)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/8347" xml:lang="en">8347</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:summary>The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0070">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:nalin_dahyabhai:vte:0.12.2"/>
          <cpe-lang:fact-ref name="cpe:/a:nalin_dahyabhai:vte:0.11.21"/>
          <cpe-lang:fact-ref name="cpe:/a:nalin_dahyabhai:vte:0.15.0"/>
          <cpe-lang:fact-ref name="cpe:/a:nalin_dahyabhai:vte:0.14.2"/>
          <cpe-lang:fact-ref name="cpe:/a:nalin_dahyabhai:vte:0.16.14"/>
          <cpe-lang:fact-ref name="cpe:/a:nalin_dahyabhai:vte:0.17.4"/>
          <cpe-lang:fact-ref name="cpe:/a:nalin_dahyabhai:vte:0.20.5"/>
          <cpe-lang:fact-ref name="cpe:/a:nalin_dahyabhai:vte:0.22.5"/>
          <cpe-lang:fact-ref name="cpe:/a:nalin_dahyabhai:vte:0.24.3"/>
          <cpe-lang:fact-ref name="cpe:/a:nalin_dahyabhai:vte:0.25.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:gnome:gnome-terminal:2.2"/>
          <cpe-lang:fact-ref name="cpe:/a:gnome:gnome-terminal:2.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nalin_dahyabhai:vte:0.22.5</vuln:product>
      <vuln:product>cpe:/a:gnome:gnome-terminal:2.2</vuln:product>
      <vuln:product>cpe:/a:nalin_dahyabhai:vte:0.25.1</vuln:product>
      <vuln:product>cpe:/a:nalin_dahyabhai:vte:0.15.0</vuln:product>
      <vuln:product>cpe:/a:nalin_dahyabhai:vte:0.17.4</vuln:product>
      <vuln:product>cpe:/a:nalin_dahyabhai:vte:0.11.21</vuln:product>
      <vuln:product>cpe:/a:nalin_dahyabhai:vte:0.12.2</vuln:product>
      <vuln:product>cpe:/a:nalin_dahyabhai:vte:0.16.14</vuln:product>
      <vuln:product>cpe:/a:gnome:gnome-terminal:2.0</vuln:product>
      <vuln:product>cpe:/a:nalin_dahyabhai:vte:0.24.3</vuln:product>
      <vuln:product>cpe:/a:nalin_dahyabhai:vte:0.20.5</vuln:product>
      <vuln:product>cpe:/a:nalin_dahyabhai:vte:0.14.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0070</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-06T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-053.html" xml:lang="en">RHSA-2003:053</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11414.php" xml:lang="en">terminal-emulator-window-title(11414)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://seclists.org/lists/bugtraq/2003/Mar/0010.html" xml:lang="en">GLSA-200303-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:summary>VTE, as used by default in gnome-terminal terminal emulator 2.2 and as an option in gnome-terminal 2.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0071">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.0.1</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.0.3</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0071</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:44.180-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11415.php" xml:lang="en">terminal-emulator-dec-udk(11415)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6950" xml:lang="en">6950</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-067.html" xml:lang="en">RHSA-2003:067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-066.html" xml:lang="en">RHSA-2003:066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-065.html" xml:lang="en">RHSA-2003:065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-064.html" xml:lang="en">RHSA-2003:064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-380" xml:lang="en">DSA-380</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:summary>The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0072">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:1.2.2.beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.3:alpha1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5_1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5_1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5_1.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.7</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:1.0</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.3:alpha1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.4</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5_1.1.1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5_1.1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.2</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.3</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.6</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:1.2.2.beta1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.5</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5_1.0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0072</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:23.723-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-266" xml:lang="en">DSA-266</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt" xml:lang="en">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-052.html" xml:lang="en">RHSA-2003:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-051.html" xml:lang="en">RHSA-2003:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7184" xml:lang="en">7184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded" xml:lang="en">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54042-1" xml:lang="en">54042</vuln:reference>
    </vuln:references>
    <vuln:summary>The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes an out-of-bounds read of an array (aka "array overrun").</vuln:summary>
  </entry>
  <entry id="CVE-2003-0073">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.31"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.36"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.41"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.47"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.52"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.53"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.54"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.54a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mysql:mysql:3.23.53</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:3.23.36</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:3.23.41</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:3.23.52</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:3.23.54</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:3.23.54a</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:3.23.47</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:3.23.31</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0073</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:44.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:436" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:436" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-303" xml:lang="en">DSA-303</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104385719107879&amp;w=2" xml:lang="en">20030129 [OpenPKG-SA-2003.008] OpenPKG Security Advisory (mysql)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mysql.com/doc/en/News-3.23.55.html" xml:lang="en">http://www.mysql.com/doc/en/News-3.23.55.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6718" xml:lang="en">6718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-166.html" xml:lang="en">RHSA-2003:166</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-094.html" xml:lang="en">RHSA-2003:094</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-093.html" xml:lang="en">RHSA-2003:093</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:013" xml:lang="en">MDKSA-2003:013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-2873.html" xml:lang="en">ESA-20030220-004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11199.php" xml:lang="en">mysql-mysqlchangeuser-doublefree-dos(11199)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000743" xml:lang="en">CLA-2003:743</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:436" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:436" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0074">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:plptools:plptools:0.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:plptools:plptools:0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0074</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:24.083-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6715" xml:lang="en">6715</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11193.php" xml:lang="en">plptools-plpnsfd-format-string(11193)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386699725019&amp;w=2" xml:lang="en">20030129 Re: Local root vuln in SuSE 8.0 plptools package</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104385772908969&amp;w=2" xml:lang="en">20030129 Local root vuln in SuSE 8.0 plptools package</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in mpmain.c for plpnfsd of the plptools package allows remote attackers to execute arbitrary code via the functions (1) debuglog, (2) errorlog, and (3) infolog.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0075">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:bladeenc:bladeenc:0.92.7"/>
        <cpe-lang:fact-ref name="cpe:/a:bladeenc:bladeenc:0.93.10"/>
        <cpe-lang:fact-ref name="cpe:/a:bladeenc:bladeenc:0.94.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bladeenc:bladeenc:0.94.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bladeenc:bladeenc:0.94.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bladeenc:bladeenc:0.92.7</vuln:product>
      <vuln:product>cpe:/a:bladeenc:bladeenc:0.94.1</vuln:product>
      <vuln:product>cpe:/a:bladeenc:bladeenc:0.93.10</vuln:product>
      <vuln:product>cpe:/a:bladeenc:bladeenc:0.94.2</vuln:product>
      <vuln:product>cpe:/a:bladeenc:bladeenc:0.94.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0075</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:24.240-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6745" xml:lang="en">6745</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.pivx.com/luigi/adv/blade942-adv.txt" xml:lang="en">http://www.pivx.com/luigi/adv/blade942-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104446346127432&amp;w=2" xml:lang="en">GLSA-200302-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11227.php" xml:lang="en">bladeenc-myfseek-code-execution(11227)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104428700106672&amp;w=2" xml:lang="en">20030202 Bladeenc 0.94.2 code execution</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer signedness error in the myFseek function of samplein.c for Blade encoder (BladeEnc) 0.94.2 and earlier allows remote attackers to execute arbitrary code via a negative offset value following a "fmt" wave chunk.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0076">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:dcgui:dcgui:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:dcgui:dcgui:0.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:qt-dcgui:qt-dcgui:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:qt-dcgui:qt-dcgui:0.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:qt-dcgui:qt-dcgui:0.2</vuln:product>
      <vuln:product>cpe:/a:qt-dcgui:qt-dcgui:0.2.1</vuln:product>
      <vuln:product>cpe:/a:dcgui:dcgui:0.2.1</vuln:product>
      <vuln:product>cpe:/a:dcgui:dcgui:0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0076</vuln:cve-id>
    <vuln:published-datetime>2003-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:24.443-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104437720116243&amp;w=2" xml:lang="en">20030204 GLSA:  qt-dcgui</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11246.php" xml:lang="en">qtdcgui-directory-download-files(11246)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://dc.ketelhot.de/pipermail/dc/2003-January/000094.html" xml:lang="en">http://dc.ketelhot.de/pipermail/dc/2003-January/000094.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the directory parser for Direct Connect 4 Linux (dcgui) before 0.2.2 allows remote attackers to read files outside the sharelist.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0077">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hanterm:hanterm-xf:2.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hanterm:hanterm-xf:2.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0077</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:24.600-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11414.php" xml:lang="en">terminal-emulator-window-title(11414)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-071.html" xml:lang="en">RHSA-2003:071</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-070.html" xml:lang="en">RHSA-2003:070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/4917" xml:lang="en">4917</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:summary>The hanterm (hanterm-xf) terminal emulator 2.0.5 and earlier, and possibly later versions, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0078">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.1c"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.2b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6c"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6d"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6e"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6g"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6h"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8:pre-release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openssl:openssl:0.9.4</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.5</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6h</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.2b</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6g</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6b</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6c</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.2</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.5a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6e</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8:pre-release</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.1c</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6d</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.3</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0078</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:47.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openssl.org/news/secadv_20030219.txt" xml:lang="en">http://www.openssl.org/news/secadv_20030219.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104568426824439&amp;w=2" xml:lang="en">20030219 [OpenPKG-SA-2003.013] OpenPKG Security Advisory (openssl)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11369.php" xml:lang="en">ssl-cbc-information-leak(11369)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-253" xml:lang="en">DSA-253</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2003/0005" xml:lang="en">2003-0005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6884" xml:lang="en">6884</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-205.html" xml:lang="en">RHSA-2003:205</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-104.html" xml:lang="en">RHSA-2003:104</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-082.html" xml:lang="en">RHSA-2003:082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-063.html" xml:lang="en">RHSA-2003:063</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-062.html" xml:lang="en">RHSA-2003:062</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3945" xml:lang="en">3945</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:020" xml:lang="en">MDKSA-2003:020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-2874.html" xml:lang="en">ESA-20030220-005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-051.shtml" xml:lang="en">N-051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104577183206905&amp;w=2" xml:lang="en">GLSA-200302-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104567627211904&amp;w=2" xml:lang="en">20030219 OpenSSL 0.9.7a and 0.9.6i released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000570" xml:lang="en">CLSA-2003:570</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I" xml:lang="en">20030501-01-I</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.asc" xml:lang="en">NetBSD-SA2003-001</vuln:reference>
    </vuln:references>
    <vuln:summary>ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0079">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hanterm:hanterm-xf:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hanterm:hanterm-xf:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0079</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:47.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11415.php" xml:lang="en">terminal-emulator-dec-udk(11415)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6944" xml:lang="en">6944</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-071.html" xml:lang="en">RHSA-2003:071</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-070.html" xml:lang="en">RHSA-2003:070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/4918" xml:lang="en">4918</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" xml:lang="en">20030224 Terminal Emulator Security Issues</vuln:reference>
    </vuln:references>
    <vuln:summary>The DEC UDK processing feature in the hanterm (hanterm-xf) terminal emulator before 2.0.5 allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0080">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnome:gnome-lokkit:0.50_21"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnome:gnome-lokkit:0.50_21</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0080</vuln:cve-id>
    <vuln:published-datetime>2003-03-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:25.130-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7128" xml:lang="en">7128</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-072.html" xml:lang="en">RHSA-2003:072</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11552" xml:lang="en">gnomelokkit-forward-bypass-firewall(11552)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/4400" xml:lang="en">4400</vuln:reference>
    </vuln:references>
    <vuln:summary>The iptables ruleset in Gnome-lokkit in Red Hat Linux 8.0 does not include any rules in the FORWARD chain, which could allow attackers to bypass intended access restrictions if packet forwarding is enabled.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0081">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.8.18"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.8</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.7</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.0</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.3</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.1</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.2</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.9</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.4</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.5</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.6</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.8.18</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0081</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:25.287-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:54" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:54" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7049" xml:lang="en">7049</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.guninski.com/etherre.html" xml:lang="en">http://www.guninski.com/etherre.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00008.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00008.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-258" xml:lang="en">DSA-258</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11497" xml:lang="en">ethereal-socks-format-string(11497)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-077.html" xml:lang="en">RHSA-2003:077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-076.html" xml:lang="en">RHSA-2003:076</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_019_ethereal.html" xml:lang="en">SuSE-SA:2003:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/gentoo_advisory-2949.html" xml:lang="en">GLSA-200303-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://seclists.org/lists/fulldisclosure/2003/Mar/0080.html" xml:lang="en">20030308 Ethereal format string bug, yet still ethereal much better than windows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2003:051" xml:lang="en">MDKSA-2003:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000627" xml:lang="en">CLSA-2003:627</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:54" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:54" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0082">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:1.2.2.beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.3:alpha1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5_1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5_1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5_1.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.7</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:1.0</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.3:alpha1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.4</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5_1.1.1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5_1.1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.2</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.3</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.6</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:1.2.2.beta1</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5-1.2.5</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5_1.0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0082</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:52.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4430" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4430" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2536" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2536" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:244" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:244" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-266" xml:lang="en">DSA-266</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt" xml:lang="en">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-091.html" xml:lang="en">RHSA-2003:091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-052.html" xml:lang="en">RHSA-2003:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-051.html" xml:lang="en">RHSA-2003:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7185" xml:lang="en">7185</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded" xml:lang="en">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54042-1" xml:lang="en">54042</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:244" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:244" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2536" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2536" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4430" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4430" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").</vuln:summary>
  </entry>
  <entry id="CVE-2003-0083">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:1.3</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0083</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:52.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:151" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:151" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-139.html" xml:lang="en">RHSA-2003:139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108034113406858&amp;w=2" xml:lang="en">20040325 LNSA-#2004-0006: bug workaround for Apache 2.0.48</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/loggers/mod_log_config.c?only_with_tag=APACHE_2_0_BRANCH" xml:lang="en">http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/loggers/mod_log_config.c?only_with_tag=APACHE_2_0_BRANCH</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.apache.org/viewcvs.cgi/apache-1.3/src/modules/standard/mod_log_config.c?only_with_tag=APACHE_1_3_25" xml:lang="en">http://cvs.apache.org/viewcvs.cgi/apache-1.3/src/modules/standard/mod_log_config.c?only_with_tag=APACHE_1_3_25</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8146" xml:lang="en">8146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108024081011678&amp;w=2" xml:lang="en">20040325 GLSA200403-04 Multiple security vulnerabilities in Apache 2</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:151" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:151" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0084">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mod_auth_any:mod_auth_any:1.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mod_auth_any:mod_auth_any:1.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0084</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:25.787-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7448" xml:lang="en">7448</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2003-114.html" xml:lang="en">RHSA-2003:114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11893" xml:lang="en">modauthany-command-execution(11893)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-113.html" xml:lang="en">RHSA-2003:113</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.itlab.musc.edu/webNIS/mod_auth_any.html" xml:lang="en">http://www.itlab.musc.edu/webNIS/mod_auth_any.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-090.shtml" xml:lang="en">N-090</vuln:reference>
    </vuln:references>
    <vuln:summary>mod_auth_any package in Red Hat Enterprise Linux 2.1 and other operating systems does not properly escape arguments when calling other programs, which allows attackers to execute arbitrary commands via shell metacharacters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0085">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.1a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.3a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.7a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.05"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.06"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.07"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.08"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.08.01"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.09"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.09.01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:samba:samba:2.2.3a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.7a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.8</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.0a</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.09</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.1</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.06</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.09.01</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.5</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.08.01</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.1a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.7</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.05</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.2</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.08</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.9</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.07</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0085</vuln:cve-id>
    <vuln:published-datetime>2003-03-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:12:07.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:552" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:552" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/298233" xml:lang="en">VU#298233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7106" xml:lang="en">7106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-262" xml:lang="en">DSA-262</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792723017768&amp;w=2" xml:lang="en">20030317 Security Bugfix for Samba - Samba 2.2.8 Released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792646416629&amp;w=2" xml:lang="en">20030317 GLSA:  samba (200303-11)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IMMUNIX</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/317145/30/25220/threaded" xml:lang="en">IMNX-2003-7+-003-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded" xml:lang="en">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-095.html" xml:lang="en">RHSA-2003:095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_016_samba.html" xml:lang="en">SuSE-SA:2003:016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030302-01-I" xml:lang="en">20030302-01-I</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IMMUNIX</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/317145/30/25220/threaded" xml:lang="en">IMNX-2003-7+-003-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded" xml:lang="en">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-096.html" xml:lang="en">RHSA-2003:096</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:032" xml:lang="en">MDKSA-2003:032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200303-11.xml" xml:lang="en">GLSA-200303-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8303" xml:lang="en">8303</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8299" xml:lang="en">8299</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104801012929374&amp;w=2" xml:lang="en">20030318 [OpenPKG-SA-2003.021] OpenPKG Security Advisory (samba)</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:552" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:552" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0086">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.1a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.3a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.7a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:samba:samba:2.2.3a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.7a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.0a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.8</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.1a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0086</vuln:cve-id>
    <vuln:published-datetime>2003-03-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:12:07.220-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>1.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:554" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:554" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7107" xml:lang="en">7107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-262" xml:lang="en">DSA-262</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792646416629&amp;w=2" xml:lang="en">20030317 GLSA:  samba (200303-11)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded" xml:lang="en">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-095.html" xml:lang="en">RHSA-2003:095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_016_samba.html" xml:lang="en">SuSE-SA:2003:016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030302-01-I" xml:lang="en">20030302-01-I</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded" xml:lang="en">APPLE-SA-2003-03-24</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-096.html" xml:lang="en">RHSA-2003:096</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:032" xml:lang="en">MDKSA-2003:032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200303-11.xml" xml:lang="en">GLSA-200303-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8303" xml:lang="en">8303</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8299" xml:lang="en">8299</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104801012929374&amp;w=2" xml:lang="en">20030318 [OpenPKG-SA-2003.021] OpenPKG Security Advisory (samba)</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:554" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:554" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0087">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:national_language_support:libim"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:national_language_support:libim</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0087</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:47.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/02.12.03.txt" xml:lang="en">http://www.idefense.com/advisory/02.12.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11309" xml:lang="en">aix-aixterm-libim-bo(11309)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6840" xml:lang="en">6840</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/7996" xml:lang="en">7996</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40320&amp;apar=only" xml:lang="en">IY40320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40317&amp;apar=only" xml:lang="en">IY40317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40307&amp;apar=only" xml:lang="en">IY40307</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104508833214691&amp;w=2" xml:lang="en">20030212 libIM.a buffer overflow vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104508375107938&amp;w=2" xml:lang="en">20030212 iDEFENSE Security Advisory 02.12.03: Buffer Overflow in AIX libIM.a</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0066.html" xml:lang="en">20030212 iDEFENSE Security Advisory 02.12.03: Buffer Overflow in AIX libIM.a</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in libIM library (libIM.a) for National Language Support (NLS) on AIX 4.3 through 5.2 allows local users to gain privileges via several possible attack vectors, including a long -im argument to aixterm.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0088">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0088</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:48.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a021403-1.txt" xml:lang="en">A021403-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11332.php" xml:lang="en">macos-trublueenvironment-gain-privileges(11332)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" xml:lang="en">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6859" xml:lang="en">6859</vuln:reference>
    </vuln:references>
    <vuln:summary>TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable that is used to write debugging information.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0089">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0089</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-03-04T00:17:31.170-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5466" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5466" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/13623" xml:lang="en">hp-sd-utilities-bo(13623)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8986" xml:lang="en">8986</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/6030" xml:lang="en">HPSBUX0311-293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106873965001431&amp;w=2" xml:lang="en">20031113 NSFOCUS SA2003-07: HP-UX Software Distributor Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0038.html" xml:lang="en">20031113 NSFOCUS SA2003-07: HP-UX Software Distributor Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5466" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5466" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the Software Distributor utilities for HP-UX B.11.00 and B.11.11 allows local users to execute arbitrary code via a long LANG environment variable to setuid programs such as (1) swinstall and (2) swmodify.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0090">
    <vuln:cve-id>CVE-2003-0090</vuln:cve-id>
    <vuln:published-datetime>2003-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:53.633-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2000-0844.  Reason: This candidate is a duplicate of CVE-2000-0844.  Notes: All CVE users should reference CVE-2000-0844 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0091">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0091</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:54.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4383" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4383" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0162.html" xml:lang="en">20030331 NSFOCUS SA2003-02: Solaris lpq Stack Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/316957/30/25250/threaded" xml:lang="en">20030331 NSFOCUS SA2003-02: Solaris lpq Stack Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/8713" xml:lang="en">8713</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nsfocus.com/english/homepage/sa2003-02.htm" xml:lang="en">http://www.nsfocus.com/english/homepage/sa2003-02.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-068.shtml" xml:lang="en">N-068</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52443-1" xml:lang="en">52443</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://packetstormsecurity.org/0304-advisories/sa2003-02.txt" xml:lang="en">http://packetstormsecurity.org/0304-advisories/sa2003-02.txt</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4383" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4383" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Stack-based buffer overflow in the bsd_queue() function for lpq on Solaris 2.6 and 7 allows local users to gain root privilege.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0092">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0092</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:54.133-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1905" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1905" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0163.html" xml:lang="en">20030331 NSFOCUS SA2003-03: Solaris dtsession Heap Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7240" xml:lang="en">7240</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/316948/30/25250/threaded" xml:lang="en">20030331 NSFOCUS SA2003-03: Solaris dtsession Heap Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52388-1" xml:lang="en">52388</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1905" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1905" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0093">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.4a6"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lbl:tcpdump:3.6.2</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.5.2</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.4a6</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.5</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0093</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:54.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=81585" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=81585</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11324" xml:lang="en">tcpdump-radius-decoder-dos(11324)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-214.html" xml:lang="en">RHSA-2003:214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-033.html" xml:lang="en">RHSA-2003:033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-032.html" xml:lang="en">RHSA-2003:032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027" xml:lang="en">MDKSA-2003:027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-261" xml:lang="en">DSA-261</vuln:reference>
    </vuln:references>
    <vuln:summary>The RADIUS decoder in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service (crash) via an invalid RADIUS packet with a header length field of 0, which causes tcpdump to generate data within an infinite loop.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0094">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:util-linux:2.11n"/>
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:util-linux:2.11u"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:andries_brouwer:util-linux:2.11n</vuln:product>
      <vuln:product>cpe:/a:andries_brouwer:util-linux:2.11u</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0094</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:48.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11318" xml:lang="en">utillinux-mcookie-cookie-predictable(11318)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6855" xml:lang="en">6855</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:016" xml:lang="en">MDKSA-2003:016</vuln:reference>
    </vuln:references>
    <vuln:summary>A patch for mcookie in the util-linux package for Mandrake Linux 8.2 and 9.0 uses /dev/urandom instead of /dev/random, which causes mcookie to use an entropy source that is more predictable than expected, which may make it easier for certain types of attacks to succeed.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0095">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:oracle8i:8.1.7</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.1.3</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.1.7.1</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.2.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.2.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.1.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0095</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/953746" xml:lang="en">VU#953746</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-05.html" xml:lang="en">CA-2003-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://otn.oracle.com/deploy/security/pdf/2003alert51.pdf" xml:lang="en">http://otn.oracle.com/deploy/security/pdf/2003alert51.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6849" xml:lang="en">6849</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6319" xml:lang="en">6319</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11328.php" xml:lang="en">oracle-username-bo(11328)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-046.shtml" xml:lang="en">N-046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104549693426042&amp;w=2" xml:lang="en">20030217 Oracle unauthenticated remote system compromise (#NISR16022003a)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable through client applications that perform their own authentication, as demonstrated using LOADPSP.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0096">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:oracle8i:8.1.7</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.1.3</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.1.7.1</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.2.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.2.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.1.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0096</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/840666" xml:lang="en">VU#840666</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/743954" xml:lang="en">VU#743954</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/663786" xml:lang="en">VU#663786</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-05.html" xml:lang="en">CA-2003-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6850" xml:lang="en">6850</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6848" xml:lang="en">6848</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6847" xml:lang="en">6847</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/ora-tzofstbo.txt" xml:lang="en">http://www.nextgenss.com/advisories/ora-tzofstbo.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/ora-tmstmpbo.txt" xml:lang="en">http://www.nextgenss.com/advisories/ora-tmstmpbo.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/ora-bfilebo.txt" xml:lang="en">http://www.nextgenss.com/advisories/ora-bfilebo.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11327.php" xml:lang="en">oracle-totimestamptz-bo(11327)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11326.php" xml:lang="en">oracle-tzoffset-bo(11326)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11325.php" xml:lang="en">oracle-bfilename-directory-bo(11325)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-046.shtml" xml:lang="en">N-046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://otn.oracle.com/deploy/security/pdf/2003alert50.pdf" xml:lang="en">http://otn.oracle.com/deploy/security/pdf/2003alert50.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://otn.oracle.com/deploy/security/pdf/2003alert49.pdf" xml:lang="en">http://otn.oracle.com/deploy/security/pdf/2003alert49.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://otn.oracle.com/deploy/security/pdf/2003alert48.pdf" xml:lang="en">http://otn.oracle.com/deploy/security/pdf/2003alert48.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550346303295&amp;w=2" xml:lang="en">20030217 Oracle bfilename function buffer overflow vulnerability (#NISR16022003e)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104549782327321&amp;w=2" xml:lang="en">20030217 Oracle TZ_OFFSET Remote System Buffer Overrun (#NISR16022003c)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104549743326864&amp;w=2" xml:lang="en">20030217 Oracle TO_TIMESTAMP_TZ Remote System Buffer Overrun (#NISR16022003b)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0083.html" xml:lang="en">20030217 Oracle bfilename function buffer overflow vulnerability (#NISR16022003e)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0075.html" xml:lang="en">20030217 Oracle TZ_OFFSET Remote System Buffer Overrun (#NISR16022003c)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0073.html" xml:lang="en">20030217 Oracle unauthenticated remote system compromise (#NISR16022003a)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTAMP_TZ function, (2) a long time zone argument to the TZ_OFFSET function, or (3) a long DIRECTORY parameter to the BFILENAME function.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0097">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0097</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:49.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104567042700840&amp;w=2" xml:lang="en">GLSA-200302-09</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550977011668&amp;w=2" xml:lang="en">20030217 PHP Security Advisory: CGI vulnerability in PHP version 4.3.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.slackware.com/changelog/current.php?cpu=i386" xml:lang="en">http://www.slackware.com/changelog/current.php?cpu=i386</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11343.php" xml:lang="en">php-cgi-sapi-access(11343)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6875" xml:lang="en">6875</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104567137502557&amp;w=2" xml:lang="en">GLSA-200302-09.1</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0098">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apc:apcupsd:3.10.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apc:apcupsd:3.8.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apc:apcupsd:3.8.5</vuln:product>
      <vuln:product>cpe:/a:apc:apcupsd:3.10.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0098</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:55.897-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-277" xml:lang="en">DSA-277</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7200" xml:lang="en">7200</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_022_apcupsd.html" xml:lang="en">SuSE-SA:2003:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11334.php" xml:lang="en">apcupsd-logevent-format-string(11334)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=137900" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=137900</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006108" xml:lang="en">1006108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://hsj.shadowpenguin.org/misc/apcupsd_exp.txt" xml:lang="en">http://hsj.shadowpenguin.org/misc/apcupsd_exp.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/apcupsd/apcupsd/src/apcnisd.c.diff?r1=1.5&amp;r2=1.6" xml:lang="en">http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/apcupsd/apcupsd/src/apcnisd.c.diff?r1=1.5&amp;r2=1.6</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-015.0.txt" xml:lang="en">CSSA-2003-015.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6828" xml:lang="en">6828</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:018" xml:lang="en">MDKSA-2003:018</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0099">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apc:apcupsd:3.8.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apc:apcupsd:3.8.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0099</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:55.960-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-277" xml:lang="en">DSA-277</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7200" xml:lang="en">7200</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11491.php" xml:lang="en">apcupsd-vsprintf-multiple-bo(11491)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=137900" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=137900</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=137892" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=137892</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_022_apcupsd.html" xml:lang="en">SuSE-SA:2003:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:018" xml:lang="en">MDKSA-2003:018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006108" xml:lang="en">1006108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-015.0.txt" xml:lang="en">CSSA-2003-015.0</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arbitrary code, related to usage of the vsprintf function.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0100">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2813%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2813%29aa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2813%29ca"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2813%29ia"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2815%29aa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2815%29ca"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2815%29ia"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2816%29aa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2816%29ia"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2817%29cc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2817%29ct"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2820%29aa4"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2824a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2824b%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2828a%29ct"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2828a%29ia"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2836%29ca2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2836%29cc2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2836%29cc4"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%287%29aa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%287%29ca"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%289%29ia"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1aa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1ca"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1cc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1ct"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1ia"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2810%29bc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2811b%29t2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2817%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2819%29gs0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2819a%29gs6"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2823a%29bc1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2826%29p2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2826a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2826b%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%284%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%284%29f"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%284%29f1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%284%29xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%284%29xaf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%288%29p"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%288%29sa1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%288%29sa3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%288%29sa5"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%288.9%29sa6"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%289%29p"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%289%29xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2bc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2f"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2gs"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2p"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2sa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2wa3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2wa4"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%281%29ed"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%281%29t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%2811%29b"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%2811b%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%2811b%29t2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%2811c%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%282%29xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%287%29db1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%288%29db2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3aa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3da"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3db"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3ha"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3ma"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3na"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3wa4"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29w"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29xa3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29xb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2810%29s7"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2810%29w5"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2810%29w5%2818f%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2810%29w5%2818g%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2810a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2811%29s6"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2811%29st4"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2811a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2812%29s3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2812a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2813%29s6"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2813%29w5%2819c%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2813%29wt6%281%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2813a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2814%29s7"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2814%29st"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2814%29st3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2814%29w5%2820%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2814a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2815%29s3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2815%29s6"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2815a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816%29s8"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816%29sc3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816%29st1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816%29w5%2821%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816.06%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2816a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29s4"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29sl2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29sl6"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29st1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817%29st5"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2817a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2818%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2818%29s5"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2818%29st1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2818%29w5%2822b%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%2818b%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282b%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%283%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%283%29t2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%283d%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%284%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%284%29t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%284%29xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%284%29xe1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%284%29xm"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%284%29xm1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29t1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29wc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29wc2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29wc2b"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29wc3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29wc3b"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29wx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xk"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xk2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xn"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xn1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xs"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29xu"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285%29yb4"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285.1%29xp"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285.2%29xu"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285.3%29wc1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%285.4%29wc1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%286b%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29db2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29dc1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29s1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29sc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29t2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29wx5%2815a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xe2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xf1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xk"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xk3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287%29xv"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287.4%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%287a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%288%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%288%29s1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%288.0.2%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%288.3%29sc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%288a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%289%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%289%29s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%289%29s8"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%289a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0da"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0db"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0dc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sp"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0st"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0w5"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0wc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0wt"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0wx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xh"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xi"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xj"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xk"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xm"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xn"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xp"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xq"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xr"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xs"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xu"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xv"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xw"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:11.1%2820%29aa4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2gs</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%282%29xc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%2819%29gs0.2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%281%29t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%281%29ed</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2810%29w5%2818f%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%2810%29bc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2817%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%281%29xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%284%29f</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29wc3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%283%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%287%29aa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2817%29ct</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2814%29w5%2820%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29xe2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29xf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xw</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%2811c%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%2826b%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2811%29s6</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2828a%29ct</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%289a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0db</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%284%29xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%288%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29t2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29wc2b</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%289%29p</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29xk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0dc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29db2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2f</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2813%29ia</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29wx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2816%29ia</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29xn1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2813%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29t1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%288%29sa5</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2836%29cc2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2817%29st1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2817%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2815%29aa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29wx5%2815a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2813%29wt6%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%288.3%29sc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285.4%29wc1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29xu</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2816%29w5%2821%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2814%29st</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%282%29xd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29xk3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285.2%29xu</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%2811%29b</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%288%29s1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2813a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%288%29db2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2813%29aa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%288%29p</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2836%29ca2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xs</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2814%29st3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2810a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2815%29s6</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2816%29s8</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2810%29s7</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%281%29xb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29xk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29sc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2sa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2836%29cc4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2816%29aa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%284%29xm1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3na</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29s1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xu</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%2811b%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2815a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2817%29s4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2812%29s3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3ha</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2811%29st4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29xs</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2816%29st1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2815%29ia</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xq</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%281%29w</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3wa4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%2819a%29gs6</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2814a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2814%29s7</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%289%29s8</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0da</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%2826a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%282b%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%2826%29p2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2817a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29xk2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%2811b%29t2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2816a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2815%29ca</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xn</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2817%29sl2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%289%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%289%29xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%283%29t2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%282%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%284%29xm</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2818%29s5</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1ia</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%284%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2817%29sl6</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%288%29sa1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29wc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0wt</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29wc2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2824a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3db</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xm</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0w5</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2812a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2817%29st5</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2818%29w5%2822b%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%284%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3ma</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%284%29f1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%287%29ca</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2wa4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285.1%29xp</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1ca</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1ct</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%284%29xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2p</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2816%29sc3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1cc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3aa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2817%29cc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29yb4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%286b%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3da</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%288a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%2823a%29bc1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2818%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2bc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%289%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%283d%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29xn</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2810%29w5%2818g%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xi</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29dc1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xr</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2811a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1aa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%282%29xf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2818b%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xp</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%287%29db1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2824b%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29xv</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2813%29w5%2819c%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%2817%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287.4%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0wx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2828a%29ia</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285%29wc3b</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%282%29xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%282%29xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xj</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0st</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%284%29xaf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%288%29sa3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2818%29st1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%288.9%29sa6</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2813%29ca</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%288.0.2%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%289%29ia</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%284%29t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%284%29xe1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2wa3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2816.06%29s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%287%29xf1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0wc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2813%29s6</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%285.3%29wc1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sp</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xv</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%2811b%29t2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%281%29xa3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%282%29xg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2810%29w5</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%2815%29s3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0100</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:49.507-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104587206702715&amp;w=2" xml:lang="en">20030221 Re: Cisco IOS OSPF exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11373.php" xml:lang="en">cisco-ios-ospf-bo(11373)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104576100719090&amp;w=2" xml:lang="en">20030220 Cisco IOS OSPF exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6895" xml:lang="en">6895</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5565" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5565" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a large number of OSPF neighbor announcements.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0101">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:engardelinux:guardian_digital_webtool:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.91"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.92"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.93"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.94"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.95"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.96"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.97"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.98"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:0.99"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.0.50"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.0.60"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:usermin:usermin:0.6</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.96</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.0.60</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.5</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.9</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.99</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.4</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.95</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.7</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.0.50</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.8</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.91</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.94</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.97</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.92</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.93</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:0.98</vuln:product>
      <vuln:product>cpe:/a:engardelinux:guardian_digital_webtool:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0101</vuln:cve-id>
    <vuln:published-datetime>2003-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:49.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=webmin-announce&amp;m=104587858408101&amp;w=2" xml:lang="en">http://marc.theaimsgroup.com/?l=webmin-announce&amp;m=104587858408101&amp;w=2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610300325629&amp;w=2" xml:lang="en">20030224 [SNS Advisory No.62] Webmin/Usermin Session ID Spoofing Vulnerability "Episode 2"</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6915" xml:lang="en">6915</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.lac.co.jp/security/english/snsadv_e/62_e.html" xml:lang="en">http://www.lac.co.jp/security/english/snsadv_e/62_e.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11390.php" xml:lang="en">webmin-usermin-root-access(11390)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-319" xml:lang="en">DSA-319</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-058.shtml" xml:lang="en">N-058</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610336226274&amp;w=2" xml:lang="en">20030224 GLSA:  usermin (200302-14)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610245624895&amp;w=2" xml:lang="en">20030224 Webmin 1.050 - 1.060 remote exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/linux/engarde/2003-q1/0008.html" xml:lang="en">ESA-20030225-006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/hp/2003-q1/0063.html" xml:lang="en">HPSBUX0303-250</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030602-01-I" xml:lang="en">20030602-01-I</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006160" xml:lang="en">1006160</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:025" xml:lang="en">MDKSA-2003:025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/gentoo_advisory-2886.html" xml:lang="en">http://www.linuxsecurity.com/advisories/gentoo_advisory-2886.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8163" xml:lang="en">8163</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8115" xml:lang="en">8115</vuln:reference>
    </vuln:references>
    <vuln:summary>miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0102">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:file:file:3.28"/>
        <cpe-lang:fact-ref name="cpe:/a:file:file:3.30"/>
        <cpe-lang:fact-ref name="cpe:/a:file:file:3.32"/>
        <cpe-lang:fact-ref name="cpe:/a:file:file:3.33"/>
        <cpe-lang:fact-ref name="cpe:/a:file:file:3.34"/>
        <cpe-lang:fact-ref name="cpe:/a:file:file:3.35"/>
        <cpe-lang:fact-ref name="cpe:/a:file:file:3.36"/>
        <cpe-lang:fact-ref name="cpe:/a:file:file:3.37"/>
        <cpe-lang:fact-ref name="cpe:/a:file:file:3.39"/>
        <cpe-lang:fact-ref name="cpe:/a:file:file:3.40"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:file:file:3.34</vuln:product>
      <vuln:product>cpe:/a:file:file:3.39</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.3</vuln:product>
      <vuln:product>cpe:/a:file:file:3.30</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5</vuln:product>
      <vuln:product>cpe:/a:file:file:3.33</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6</vuln:product>
      <vuln:product>cpe:/a:file:file:3.35</vuln:product>
      <vuln:product>cpe:/a:file:file:3.36</vuln:product>
      <vuln:product>cpe:/a:file:file:3.37</vuln:product>
      <vuln:product>cpe:/a:file:file:3.32</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.2</vuln:product>
      <vuln:product>cpe:/a:file:file:3.28</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.5.1</vuln:product>
      <vuln:product>cpe:/a:file:file:3.40</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0102</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:56.180-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/611865" xml:lang="en">VU#611865</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7008" xml:lang="en">7008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/03.04.03.txt" xml:lang="en">http://www.idefense.com/advisory/03.04.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11469" xml:lang="en">file-afctr-read-bo(11469)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-087.html" xml:lang="en">RHSA-2003:087</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-086.html" xml:lang="en">RHSA-2003:086</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_017_file.html" xml:lang="en">SuSE-SA:2003:017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:030" xml:lang="en">MDKSA-2003:030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-260" xml:lang="en">DSA-260</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104680706201721&amp;w=2" xml:lang="en">20030304 iDEFENSE Security Advisory 03.04.03: Locally Exploitable Buffer Overflow in file(1)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IMMUNIX</vuln:source>
      <vuln:reference href="http://lwn.net/Alerts/34908/" xml:lang="en">IMNX-2003-7+-012-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-003.txt.asc" xml:lang="en">NetBSD-SA2003-003</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF header (elfhdr.e_shentsize).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0103">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:nokia:6210_handset:5.27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:nokia:6210_handset:5.27</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0103</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:29.380-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6952" xml:lang="en">6952</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11421.php" xml:lang="en">nokia-6210-vcard-dos(11421)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in Nokia 6210 handset allows remote attackers to cause a denial of service (crash, lockup, or restart) via a Multi-Part vCard with fields containing a large number of format string specifiers.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0104">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.10"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.11"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.12"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.13"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.14"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.15"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.16"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.17"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.18"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.40"/>
        <cpe-lang:fact-ref name="cpe:/a:peoplesoft:peopletools:8.41"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.40</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.13</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.16</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.12</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.18</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.17</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.10</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.14</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.15</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.11</vuln:product>
      <vuln:product>cpe:/a:peoplesoft:peopletools:8.41</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0104</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:29.537-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7053" xml:lang="en">7053</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/10962.php" xml:lang="en">peoplesoft-schedulertransfer-create-files(10962)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21999" xml:lang="en">20030310 PeopleSoft PeopleTools Remote Command Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in PeopleTools 8.10 through 8.18, 8.40, and 8.41 allows remote attackers to overwrite arbitrary files via the SchedulerTransfer servlet.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0105">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:port80_software:servermask:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:port80_software:servermask:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0105</vuln:cve-id>
    <vuln:published-datetime>2004-09-28T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:29.707-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/16947" xml:lang="en">servermask-header-obtain-info(16947)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.corsaire.com/advisories/c030224-001.txt" xml:lang="en">http://www.corsaire.com/advisories/c030224-001.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109215441332682&amp;w=2" xml:lang="en">20040810 Corsaire Security Advisory - Port80 Software ServerMask inconsistencies</vuln:reference>
    </vuln:references>
    <vuln:summary>ServerMask 2.2 and earlier does not obfuscate (1) ETag, (2) HTTP Status Message, or (3) Allow HTTP responses, which could tell remote attackers that the web server is an IIS server.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0106">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:symantec:enterprise_firewall:7.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:enterprise_firewall:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0106</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:29.850-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2003032507434754" xml:lang="en">http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2003032507434754</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104869513822233&amp;w=2" xml:lang="en">20030326 Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7196" xml:lang="en">7196</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0152.html" xml:lang="en">20030326 Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104868285106289&amp;w=2" xml:lang="en">20030326 Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</vuln:reference>
    </vuln:references>
    <vuln:summary>The HTTP proxy for Symantec Enterprise Firewall (SEF) 7.0 allows proxy users to bypass pattern matching for blocked URLs via requests that are URL-encoded with escapes, Unicode, or UTF-8.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0107">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:zlib:1.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:zlib:1.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0107</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:05:50.163-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/142121" xml:lang="en">VU#142121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11381.php" xml:lang="en">zlib-gzprintf-bo(11381)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://online.securityfocus.com/archive/1/312869" xml:lang="en">20030222 buffer overrun in zlib 1.1.4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610337726297&amp;w=2" xml:lang="en">20030223 poc zlib sploit just for fun :)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00038.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00038.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6913" xml:lang="en">6913</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-081.html" xml:lang="en">RHSA-2003:081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-079.html" xml:lang="en">RHSA-2003:079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6599" xml:lang="en">6599</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:033" xml:lang="en">MDKSA-2003:033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F57405" xml:lang="en">57405</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887247624907&amp;w=2" xml:lang="en">GLSA-200303-25</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104620610427210&amp;w=2" xml:lang="en">20030225 [sorcerer-spells] ZLIB-SORCERER2003-02-25</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610536129508&amp;w=2" xml:lang="en">20030224 Re: buffer overrun in zlib 1.1.4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com/atualizacoes/?id=a&amp;anuncio=000619" xml:lang="en">CLSA-2003:619</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-004.txt.asc" xml:lang="en">NetBSD-SA2003-004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-011.0.txt" xml:lang="en">CSSA-2003-011.0</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denial of service or possibly execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0108">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lbl:tcpdump:3.7</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.6.2</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.5.2</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0108</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:30.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6974" xml:lang="en">6974</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/02.27.03.txt" xml:lang="en">http://www.idefense.com/advisory/02.27.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-255" xml:lang="en">DSA-255</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11434.php" xml:lang="en">tcpdump-isakmp-dos(11434)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-214.html" xml:lang="en">RHSA-2003:214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-085.html" xml:lang="en">RHSA-2003:085</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-032.html" xml:lang="en">RHSA-2003:032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_015_tcpdump.html" xml:lang="en">SuSE-SA:2003:0015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027" xml:lang="en">MDKSA-2003:027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104678787109030&amp;w=2" xml:lang="en">20030304 [OpenPKG-SA-2003.014] OpenPKG Security Advisory (tcpdump)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104637420104189&amp;w=2" xml:lang="en">20030227 iDEFENSE Security Advisory 02.27.03: TCPDUMP Denial of Service Vulnerability in ISAKMP Packet Parsin</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000629" xml:lang="en">CLA-2003:629</vuln:reference>
    </vuln:references>
    <vuln:summary>isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed ISAKMP packet to UDP port 500, which causes tcpdump to enter an infinite loop.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0109">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0109</vuln:cve-id>
    <vuln:published-datetime>2003-03-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:57.290-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:109" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:109" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-09.html" xml:lang="en">CA-2003-09</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/117394" xml:lang="en">VU#117394</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7116" xml:lang="en">7116</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms03-007.asp" xml:lang="en">MS03-007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11533.php" xml:lang="en">http-webdav-long-request(11533)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=22029" xml:lang="en">20030317 Microsoft IIS WebDAV Remote Compromise Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/papers/ms03-007-ntdll.pdf" xml:lang="en">http://www.nextgenss.com/papers/ms03-007-ntdll.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q815021" xml:lang="en">Q815021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://microsoft.com/downloads/details.aspx?FamilyId=C9A38D45-5145-4844-B62E-C69D32AC929B&amp;displaylang=en" xml:lang="en">http://microsoft.com/downloads/details.aspx?FamilyId=C9A38D45-5145-4844-B62E-C69D32AC929B&amp;displaylang=en</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104826785731151&amp;w=2" xml:lang="en">20030321 New attack vectors and a vulnerability dissection of MS03-007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105768156625699&amp;w=2" xml:lang="en">20030708 WDAV exploit without netcat and with pretty magic number</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887148323552&amp;w=2" xml:lang="en">20030328 Fate Research Labs Presents: Analysis of the NTDLL.DLL Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104869293619064&amp;w=2" xml:lang="en">20030326 WebDAV exploit: using wide character decoder scheme</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104861839130254&amp;w=2" xml:lang="en">20030325 IIS 5.0 WebDAV -Proof of concept-. Fully documented.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104826476427372&amp;w=2" xml:lang="en">20030321 New attack vectors and a vulnerability dissection of MS03-007</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:109" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:109" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0110">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:isa_server:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:isa_server:2000:fp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:isa_server:2000:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:proxy_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:proxy_server:2.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:proxy_server:2.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:isa_server:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:isa_server:2000:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:isa_server:2000:fp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:proxy_server:2.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0110</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:57.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:406" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:406" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms03-012.asp" xml:lang="en">MS03-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/04.09.03.txt" xml:lang="en">http://www.idefense.com/advisory/04.09.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104994487012027&amp;w=2" xml:lang="en">20030409 iDEFENSE Security Advisory 04.09.03: Denial of Service in Microsoft Proxy Server and Internet Security and Acceleration Server 2000 </vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:406" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:406" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0111">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:virtual_machine:3802"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:virtual_machine:3805"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:virtual_machine:3809"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/a:microsoft:virtual_machine:3809</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/a:microsoft:virtual_machine:3802</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/a:microsoft:virtual_machine:3805</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0111</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:57.430-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:136" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:136" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/447569" xml:lang="en">VU#447569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms03-011.asp" xml:lang="en">MS03-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11751.php" xml:lang="en">msvm-bytecode-improper-validation(11751)</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:136" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:136" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Microsoft VM Could Enable System Compromise."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0112">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_terminal_services::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_terminal_services</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0112</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:57.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:779" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:779" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3145" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3145" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:262" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:262" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2265" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2265" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2022" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2022" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:142" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:142" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1264" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1264" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/446338" xml:lang="en">VU#446338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7370" xml:lang="en">7370</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/MS03-013.asp" xml:lang="en">MS03-013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11803" xml:lang="en">win-kernel-lpcrequestwaitreplyport-bo(11803)</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2265" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2265" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:142" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:142" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2022" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2022" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:262" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:262" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3145" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3145" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1264" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1264" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:779" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:779" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0113">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0113</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:57.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:926" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:926" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/169753" xml:lang="en">VU#169753</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp" xml:lang="en">MS03-015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105138417416900&amp;w=2" xml:lang="en">20030426 Buffer overflow in Internet Explorer's HTTP parsing code</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105718285107246&amp;w=2" xml:lang="en">20030701 URLMON.DLL buffer overflow - technical details</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:926" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:926" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0114">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0114</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:57.633-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:963" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:963" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp" xml:lang="en">MS03-015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104429340817718&amp;w=2" xml:lang="en">20030203 internet explorer local file reading</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:963" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:963" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0115">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0115</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:57.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp" xml:lang="en">MS03-015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11848.php" xml:lang="en">ie-improper-thirdparty-rendering(11848)</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed during third party rendering, which could allow remote attackers to execute arbitrary web script, aka the "Third Party Plugin Rendering" vulnerability, a different vulnerability than CVE-2003-0233.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0116">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0116</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:31.507-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/244729" xml:lang="en">VU#244729</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6306" xml:lang="en">6306</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp" xml:lang="en">MS03-015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/301945" xml:lang="en">20021203 Poisonous Style for Dialog window turns the zone off.</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs, which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and then accesses the target files, aka "Modal Dialog script execution."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0117">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2002::developer"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2002::enterprise"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2002::enterprise</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2002::developer</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0117</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:57.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms03-016.asp" xml:lang="en">MS03-016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216866132289&amp;w=2" xml:lang="en">20030505 Microsoft Biztalk Server ISAPI HTTP Receive function buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0118">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2000::developer"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2000::enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2000::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2000:sp1a:developer"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2000:sp1a:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2000:sp1a:standard"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2000:sp2:developer"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2000:sp2:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2000:sp2:standard"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2002::developer"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2002::enterprise"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2002::enterprise</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2000:sp1a:developer</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2000::standard</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2000:sp2:standard</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2000:sp2:enterprise</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2000:sp1a:enterprise</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2000:sp1a:standard</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2000::developer</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2002::developer</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2000::enterprise</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2000:sp2:developer</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0118</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:17:58.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms03-016.asp" xml:lang="en">MS03-016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216839231951&amp;w=2" xml:lang="en">20030505 Microsoft Biztalk Server DTA vulnerable to SQL injection</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0119">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:5.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0119</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:31.973-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/624713" xml:lang="en">VU#624713</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7264" xml:lang="en">7264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IBM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/services/continuity/recover1.nsf/4699c03b46f2d4f68525678c006d45ae/85256a3400529a8685256cde0008ddde?OpenDocument" xml:lang="en">MSS-OAR-E01-2003:0245.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8221" xml:lang="en">8221</vuln:reference>
    </vuln:references>
    <vuln:summary>The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorized activities.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0120">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mhc-utils:mhc-utils:0.25_snap2001-06-25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mhc-utils:mhc-utils:0.25_snap2001-06-25</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0120</vuln:cve-id>
    <vuln:published-datetime>2003-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:32.130-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>1.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-256" xml:lang="en">DSA-256</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6978" xml:lang="en">6978</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/11439.php" xml:lang="en">mhc-adb2mhc-insecure-tmp(11439)</vuln:reference>
    </vuln:references>
    <vuln:summary>adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0121">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.1</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.0</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0121</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:32.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7044" xml:lang="en">7044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104716030503607&amp;w=2" xml:lang="en">20030307 Corsaire Security Advisory - Clearswift MAILsweeper MIME attachment evasion issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316311" xml:lang="en">20030326 RE: Corsaire Security Advisory - Clearswift MAILsweeper MIME attachment evasion issue</vuln:reference>
    </vuln:references>
    <vuln:summary>Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specify a MIME-Version header field, which is processed by some mail clients.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0122">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:4.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:4.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:4.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.4::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.4a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.5:::french"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.6a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.7::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.7a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.8:::french"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.8a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.9a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.9a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:r5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.11</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.8</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.10</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.11</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:4.6.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.4a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.7a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:r5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.9</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:4.6.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.5:::french</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.4::solaris</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:4.6.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.8a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.10</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.9a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.6a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.7::solaris</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.8:::french</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.6</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.9a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0122</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:32.410-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/433489" xml:lang="en">VU#433489</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-11.html" xml:lang="en">CA-2003-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7037" xml:lang="en">7037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105101" xml:lang="en">http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104757319829443&amp;w=2" xml:lang="en">20030313 R7-0010: Buffer Overflow in Lotus Notes Protocol Authentication</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.rapid7.com/advisories/R7-0010.html" xml:lang="en">http://www.rapid7.com/advisories/R7-0010.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11526" xml:lang="en">lotus-nrpc-bo(11526)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-065.shtml" xml:lang="en">N-065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0125.html" xml:lang="en">20030313 R7-0010: Buffer Overflow in Lotus Notes Protocol Authentication</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0123">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:4.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:4.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:4.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.4::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.4a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.5:::french"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.6a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.7::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.7a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.8:::french"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.8a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0.9a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:5.0.9a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:r5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.11</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.8</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.10</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.11</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:4.6.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.4a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.7a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:r5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.9</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:4.6.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.5:::french</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.4::solaris</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:4.6.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.8a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.10</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.9a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.6a</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.7::solaris</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.8:::french</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:5.0.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.6</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0.9a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0123</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:32.600-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/411489" xml:lang="en">VU#411489</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-11.html" xml:lang="en">CA-2003-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7038" xml:lang="en">7038</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105060" xml:lang="en">http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104757545500368&amp;w=2" xml:lang="en">20030313 R7-0011: Lotus Notes/Domino Web Retriever HTTP Status Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.rapid7.com/advisories/R7-0011.html" xml:lang="en">http://www.rapid7.com/advisories/R7-0011.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11525" xml:lang="en">lotus-web-retriever-bo(11525)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-065.shtml" xml:lang="en">N-065</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0124">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:1.5h1"/>
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:1.5i"/>
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:1.5i2"/>
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:1.5j"/>
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:man:1.5k"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:andries_brouwer:man:1.5k</vuln:product>
      <vuln:product>cpe:/a:andries_brouwer:man:1.5i2</vuln:product>
      <vuln:product>cpe:/a:andries_brouwer:man:1.5j</vuln:product>
      <vuln:product>cpe:/a:andries_brouwer:man:1.5h1</vuln:product>
      <vuln:product>cpe:/a:andries_brouwer:man:1.5i</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0124</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:32.803-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7066" xml:lang="en">7066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104740927915154&amp;w=2" xml:lang="en">20030311 Vulnerability in man &lt; 1.5l</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11512" xml:lang="en">man-myxsprintf-code-execution(11512)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-134.html" xml:lang="en">RHSA-2003:134</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-133.html" xml:lang="en">RHSA-2003:133</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104802285112752&amp;w=2" xml:lang="en">GLSA-200303-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000620" xml:lang="en">CLSA-2003:620</vuln:reference>
    </vuln:references>
    <vuln:summary>man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes the my_xsprintf function to return a string with the value "unsafe," which is then executed as a program via a system call if it is in the search path of the user who runs man.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0125">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:multitech:routefinder_550_vpn:4.63"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:multitech:routefinder_550_vpn:4.63</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0125</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:32.957-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.krusesecurity.dk/advisories/routefind550bof.txt" xml:lang="en">http://www.krusesecurity.dk/advisories/routefind550bof.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.multitech.com/Routers/RF550VPN.TXT" xml:lang="en">ftp://ftp.multitech.com/Routers/RF550VPN.TXT</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11514" xml:lang="en">routefinder-vpn-options-bo(11514)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7067" xml:lang="en">7067</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a denial of service (reboot) and execute arbitrary code via a long GET /OPTIONS value.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0126">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:multitech:routefinder_550_vpn:4.64_beta"/>
        <cpe-lang:fact-ref name="cpe:/h:multitech:routefinder_550_vpn:4.63"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:multitech:routefinder_550_vpn:4.63</vuln:product>
      <vuln:product>cpe:/h:multitech:routefinder_550_vpn:4.64_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0126</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:33.083-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.krusesecurity.dk/advisories/routefind550bof.txt" xml:lang="en">http://www.krusesecurity.dk/advisories/routefind550bof.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>The web interface for SOHO Routefinder 550 firmware 4.63 and earlier, and possibly later versions, has a default "admin" account with a blank password, which could allow attackers on the LAN side to conduct unauthorized activities.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0127">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0127</vuln:cve-id>
    <vuln:published-datetime>2003-03-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:01.163-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:254" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:254" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/628849" xml:lang="en">VU#628849</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2003-098.html" xml:lang="en">RHSA-2003:098</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-145.html" xml:lang="en">RHSA-2003:145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-495" xml:lang="en">DSA-495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-423" xml:lang="en">DSA-423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-336" xml:lang="en">DSA-336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-332" xml:lang="en">DSA-332</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-312" xml:lang="en">DSA-312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-311" xml:lang="en">DSA-311</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-276" xml:lang="en">DSA-276</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-270" xml:lang="en">DSA-270</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200303-17.xml" xml:lang="en">GLSA-200303-17</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2003-088.html" xml:lang="en">RHSA-2003:088</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-020.0.txt" xml:lang="en">CSSA-2003-020.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-103.html" xml:lang="en">RHSA-2003:103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:039" xml:lang="en">MDKSA-2003:039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:038" xml:lang="en">MDKSA-2003:038</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105301461726555&amp;w=2" xml:lang="en">ESA-20030515-017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0134.html" xml:lang="en">20030317 Fwd: Ptrace hole / Linux 2.2.25</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:254" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:254" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0128">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ximian:evolution:1.0.7</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2.1</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.4</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2.2</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.3</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.1.1</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.6</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.8</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0128</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:01.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:107" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:107" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7117" xml:lang="en">7117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-108.html" xml:lang="en">RHSA-2003:108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html" xml:lang="en">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian 's Evolution Mail User Agent</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045" xml:lang="en">MDKSA-2003:045</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml" xml:lang="en">GLSA-200303-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104826470527308&amp;w=2" xml:lang="en">20030321 GLSA:  evolution (200303-18)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648" xml:lang="en">CLA-2003:648</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:107" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:107" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0129">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ximian:evolution:1.0.7</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2.1</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.4</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2.2</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.3</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.1.1</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.6</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.8</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0129</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:01.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:108" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:108" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7118" xml:lang="en">7118</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104826470527308&amp;w=2" xml:lang="en">20030321 GLSA:  evolution (200303-18)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-108.html" xml:lang="en">RHSA-2003:108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html" xml:lang="en">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian 's Evolution Mail User Agent</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045" xml:lang="en">MDKSA-2003:045</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml" xml:lang="en">GLSA-200303-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648" xml:lang="en">CLA-2003:648</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:108" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:108" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0130">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ximian:evolution:1.0.7</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2.1</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.4</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2.2</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.3</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.1.1</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.6</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.8</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0130</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:01.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:111" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:111" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7119" xml:lang="en">7119</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104826470527308&amp;w=2" xml:lang="en">20030321 GLSA:  evolution (200303-18)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-108.html" xml:lang="en">RHSA-2003:108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html" xml:lang="en">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian 's Evolution Mail User Agent</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045" xml:lang="en">MDKSA-2003:045</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml" xml:lang="en">GLSA-200303-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648" xml:lang="en">CLA-2003:648</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:111" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:111" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0131">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6c"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6d"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6e"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6g"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6h"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6i"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6d</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6i</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6e</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6h</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6b</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6c</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6g</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0131</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:12:10.750-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:461" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:461" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/888801" xml:lang="en">VU#888801</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7148" xml:lang="en">7148</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104811162730834&amp;w=2" xml:lang="en">20030319 [OpenSSL Advisory] Klima-Pokorny-Rosa attack on PKCS #1 v1.5 padding</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11586" xml:lang="en">ssl-premaster-information-leak(11586)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/316577/30/25310/threaded" xml:lang="en">20030327 Immunix Secured OS 7+ openssl update</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-102.html" xml:lang="en">RHSA-2003:102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-101.html" xml:lang="en">RHSA-2003:101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openssl.org/news/secadv_20030319.txt" xml:lang="en">http://www.openssl.org/news/secadv_20030319.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_024_openssl.html" xml:lang="en">SuSE-SA:2003:024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/immunix_advisory-3066.html" xml:lang="en">http://www.linuxsecurity.com/advisories/immunix_advisory-3066.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IMMUNIX</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/immunix_advisory-3066.html" xml:lang="en">IMNX-2003-7+-001-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-288" xml:lang="en">DSA-288</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00028.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00028.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://eprint.iacr.org/2003/052/" xml:lang="en">http://eprint.iacr.org/2003/052/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I" xml:lang="en">20030501-01-I</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-007.txt.asc" xml:lang="en">NetBSD-SA2003-007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.suse.de/de/security/2003_024_openssl.html" xml:lang="en">SuSE-SA:2003:024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/316577/30/25310/threaded" xml:lang="en">20030327 Immunix Secured OS 7+ openssl update</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.org/security/OpenPKG-SA-2003.026-openssl.html" xml:lang="en">OpenPKG-SA-2003.026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:035" xml:lang="en">MDKSA-2003:035</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200303-20.xml" xml:lang="en">GLSA-200303-20</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878215721135&amp;w=2" xml:lang="en">2003-0013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104852637112330&amp;w=2" xml:lang="en">20030324 GLSA:  openssl (200303-20)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000625" xml:lang="en">CLA-2003:625</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txt" xml:lang="en">CSSA-2003-014.0</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:461" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:461" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the "Klima-Pokorny-Rosa attack."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0132">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.35"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.44"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:2.0.28</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.35</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.44</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.32</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.9</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0132</vuln:cve-id>
    <vuln:published-datetime>2003-04-11T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-05-13T00:17:01.110-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:156" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:156" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/206537" xml:lang="en">VU#206537</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104931360606484&amp;w=2" xml:lang="en">20030402 [ANNOUNCE] Apache 2.0.45 Released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1233" xml:lang="en">ADV-2009-1233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-139.html" xml:lang="en">RHSA-2003:139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/04.08.03.txt" xml:lang="en">http://www.idefense.com/advisory/04.08.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147" xml:lang="en">http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8499" xml:lang="en">8499</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34920" xml:lang="en">34920</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00028.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00028.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105013378320711&amp;w=2" xml:lang="en">20030411 PATCH: [CAN-2003-0132] Apache 2.0.44 Denial of Service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105001663120995&amp;w=2" xml:lang="en">20030410 working apache &lt;= 2.0.44 DoS exploit for linux.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104994309010974&amp;w=2" xml:lang="en">20030408 Exploit Code Released for Apache 2.x Memory Leak</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104994239010517&amp;w=2" xml:lang="en">20030409 GLSA:  apache (200304-01)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104982175321731&amp;w=2" xml:lang="en">20030408 iDEFENSE Security Advisory 04.08.03: Denial of Service in Apache HTTP Server 2.x</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:156" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:156" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0133">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnome:gtkhtml:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gtkhtml:1.1.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnome:gtkhtml:1.1.10</vuln:product>
      <vuln:product>cpe:/a:gnome:gtkhtml:1.1.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0133</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:02.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:138" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:138" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-126.html" xml:lang="en">RHSA-2003:126</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:046" xml:lang="en">MDKSA-2003:046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000737" xml:lang="en">CLA-2003:737</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:138" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:138" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0134">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.35"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.44"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.45"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:2.0.28</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.35</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.45</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.44</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.32</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.9</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0134</vuln:cve-id>
    <vuln:published-datetime>2003-04-11T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:34.473-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104931360606484&amp;w=2" xml:lang="en">20030402 [ANNOUNCE] Apache 2.0.45 Released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.apache.org/viewcvs/apr/file_io/os2/filestat.c.diff?r1=1.34&amp;r2=1.35" xml:lang="en">http://cvs.apache.org/viewcvs/apr/file_io/os2/filestat.c.diff?r1=1.34&amp;r2=1.35</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105418115512559&amp;w=2" xml:lang="en">20030528 [SECURITY] [ANNOUNCE] Apache 2.0.46 released</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0135">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:9.0::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:linux:9.0::i386</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0135</vuln:cve-id>
    <vuln:published-datetime>2003-04-11T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:02.633-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:634" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:634" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7253" xml:lang="en">7253</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-084.html" xml:lang="en">RHSA-2003:084</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:634" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:634" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is installed as a standalone service, which inadvertently prevents vsftpd from restricting access as intended.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0136">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:astart_technologies:lprng:3.7.4"/>
        <cpe-lang:fact-ref name="cpe:/o:astart_technologies:lprng:3.8.10.1"/>
        <cpe-lang:fact-ref name="cpe:/o:astart_technologies:lprng:3.8.19"/>
        <cpe-lang:fact-ref name="cpe:/o:astart_technologies:lprng:3.8.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:astart_technologies:lprng:3.7.4</vuln:product>
      <vuln:product>cpe:/o:astart_technologies:lprng:3.8.10.1</vuln:product>
      <vuln:product>cpe:/o:astart_technologies:lprng:3.8.19</vuln:product>
      <vuln:product>cpe:/o:astart_technologies:lprng:3.8.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0136</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:02.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:423" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:423" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-142.html" xml:lang="en">RHSA-2003:142</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-285" xml:lang="en">DSA-285</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=188366" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=188366</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:423" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:423" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0137">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:nokia:sgsn_dx200"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nokia:sgsn_dx200</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0137</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:02.773-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a031303-2.txt" xml:lang="en">A031303-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8301" xml:lang="en">8301</vuln:reference>
    </vuln:references>
    <vuln:summary>SNMP daemon in the DX200 based network element for Nokia Serving GPRS support node (SGSN) allows remote attackers to read SNMP options via arbitrary community strings.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0138">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mit:kerberos:4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0138</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:02.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:248" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:248" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/623217" xml:lang="en">VU#623217</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-266" xml:lang="en">DSA-266</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt" xml:lang="en">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-091.html" xml:lang="en">RHSA-2003:091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-052.html" xml:lang="en">RHSA-2003:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-051.html" xml:lang="en">RHSA-2003:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-273" xml:lang="en">DSA-273</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-269" xml:lang="en">DSA-269</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7113" xml:lang="en">7113</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded" xml:lang="en">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104791775804776&amp;w=2" xml:lang="en">20030317 MITKRB5-SA-2003-004: Cryptographic weaknesses in Kerberos v4 protocol</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:248" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:248" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0139">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mit:kerberos:4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0139</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:02.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:250" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:250" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/442569" xml:lang="en">VU#442569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt" xml:lang="en">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104791775804776&amp;w=2" xml:lang="en">20030319 MITKRB5-SA-2003-004: Cryptographic weaknesses in Kerberos v4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-091.html" xml:lang="en">RHSA-2003:091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-052.html" xml:lang="en">RHSA-2003:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-051.html" xml:lang="en">RHSA-2003:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-273" xml:lang="en">DSA-273</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-266" xml:lang="en">DSA-266</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/317130/30/25250/threaded" xml:lang="en">20030330 GLSA: openafs (200303-26)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded" xml:lang="en">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:250" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:250" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing."</vuln:summary>
  </entry>
  <entry id="CVE-2003-0140">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.22"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.24"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.25"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.27"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mutt:mutt:1.3.24</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.12</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.25</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.17</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.16</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.22</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.4.0</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.27</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0140</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:02.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:434" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:434" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7120" xml:lang="en">7120</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104818814931378&amp;w=2" xml:lang="en">20030320 CORE-20030304-02: Vulnerability in Mutt Mail User Agent</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11583" xml:lang="en">mutt-folder-name-bo(11583)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/315679" xml:lang="en">20030319 mutt-1.4.1 fixes a buffer overflow.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-109.html" xml:lang="en">RHSA-2003:109</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_020_mutt.html" xml:lang="en">SuSE-SA:2003:020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-268" xml:lang="en">DSA-268</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:041" xml:lang="en">MDKSA-2003:041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200303-19.xml" xml:lang="en">GLSA-200303-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=310&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=310&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105171507629573&amp;w=2" xml:lang="en">20030430 GLSA:  balsa (200304-10)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104852190605988&amp;w=2" xml:lang="en">20030322 GLSA:  mutt (200303-19)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104817995421439&amp;w=2" xml:lang="en">20030320 [OpenPKG-SA-2003.025] OpenPKG Security Advisory (mutt)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000630" xml:lang="en">CLA-2003:630</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000626" xml:lang="en">CLA-2003:626</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:434" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:434" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0141">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_enterprise_desktop:6.0.11.774"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:6.0.10.505:gold"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:6.0.11.818"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:6.0.11.830"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:6.0.11.841"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:6.0.11.853"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:9.0.0.288"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:9.0.0.297"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:realnetworks:realplayer:8.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:6.0.10.505:gold</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:2.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:6.0.11.841</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:6.0.11.830</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:9.0.0.297</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:6.0.11.853</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:9.0.0.288</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:6.0.11.818</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_enterprise_desktop:6.0.11.774</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0141</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:12:11.487-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/705761" xml:lang="en">VU#705761</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7177" xml:lang="en">7177</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=311&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=311&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887465427579&amp;w=2" xml:lang="en">20030328 CORE-2003-0306: RealPlayer PNG deflate heap corruption vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0156.html" xml:lang="en">20030328 CORE-2003-0306: RealPlayer PNG deflate heap corruption vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>The PNG deflate algorithm in RealOne Player 6.0.11.x and earlier, RealPlayer 8/RealPlayer Plus 8 6.0.9.584, and other versions allows remote attackers to corrupt the heap and overwrite arbitrary memory via a PNG graphic file format containing compressed data using fixed trees that contain the length values 286-287, which are treated as a very large length.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0142">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0142</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:35.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/689835" xml:lang="en">VU#689835</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/328224" xml:lang="en">20030708 Adobe Acrobat and PDF security: no improvements for 2 years</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Acrobat Reader (acroread) 6, under certain circumstances when running with the "Certified plug-ins only" option disabled, loads plug-ins with signatures used for older versions of Acrobat, which can allow attackers to cause Acrobat to enter Certified mode and run untrusted plugins by modifying the CTIsCertifiedMode function.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0143">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:qpopper:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:qpopper:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:qpopper:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:qpopper:4.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:qualcomm:qpopper:4.0.1</vuln:product>
      <vuln:product>cpe:/a:qualcomm:qpopper:4.0.4</vuln:product>
      <vuln:product>cpe:/a:qualcomm:qpopper:4.0.3</vuln:product>
      <vuln:product>cpe:/a:qualcomm:qpopper:4.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0143</vuln:cve-id>
    <vuln:published-datetime>2003-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:35.910-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7058" xml:lang="en">7058</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-259" xml:lang="en">DSA-259</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11516" xml:lang="en">qpopper-popmsg-macroname-bo(11516)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104739841223916&amp;w=2" xml:lang="en">20030310 QPopper 4.0.x buffer overflow vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_018_qpopper.html" xml:lang="en">SuSE-SA:2003:018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792541215354&amp;w=2" xml:lang="en">GLSA-200303-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104768137314397&amp;w=2" xml:lang="en">20030314 [OpenPKG-SA-2003.018] OpenPKG Security Advisory (qpopper)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104748775900481&amp;w=2" xml:lang="en">20030312 Re: QPopper 4.0.x buffer overflow vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0144">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:lprold:lprold:3.0.48"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsd:lpr:0.48"/>
        <cpe-lang:fact-ref name="cpe:/o:bsd:lpr:2000-05-07"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.9"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:openbsd:openbsd:2.4</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.0</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.1</vuln:product>
      <vuln:product>cpe:/o:bsd:lpr:0.48</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.5</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.0</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.3</vuln:product>
      <vuln:product>cpe:/a:lprold:lprold:3.0.48</vuln:product>
      <vuln:product>cpe:/o:bsd:lpr:2000-05-07</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.4</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.3</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.1</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.8</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.5</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.2</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.9</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.6</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0144</vuln:cve-id>
    <vuln:published-datetime>2003-03-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:03.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7025" xml:lang="en">7025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11473" xml:lang="en">lprm-bo(11473)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_014_lprold.html" xml:lang="en">SuSE-SA:2003:0014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-275" xml:lang="en">DSA-275</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-267" xml:lang="en">DSA-267</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030406-02-P" xml:lang="en">20030406-02-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/010_lprm.patch" xml:lang="en">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/010_lprm.patch</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:059" xml:lang="en">MDKSA-2003:059</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8293" xml:lang="en">8293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104714441925019&amp;w=2" xml:lang="en">20030308 OpenBSD lprm(1) exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104690434504429&amp;w=2" xml:lang="en">20030305 potential buffer overflow in lprm (fwd)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0145">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lbl:tcpdump:3.7</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.6.2</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.5.2</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0145</vuln:cve-id>
    <vuln:published-datetime>2003-03-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:36.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.tcpdump.org/tcpdump-changes.txt" xml:lang="en">http://www.tcpdump.org/tcpdump-changes.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11857" xml:lang="en">tcpdump-radius-attribute-dos(11857)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-214.html" xml:lang="en">RHSA-2003:214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-151.html" xml:lang="en">RHSA-2003:151</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-032.html" xml:lang="en">RHSA-2003:032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027" xml:lang="en">MDKSA-2003:027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-261" xml:lang="en">DSA-261</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in tcpdump before 3.7.2 related to an inability to "Handle unknown RADIUS attributes properly," allows remote attackers to cause a denial of service (infinite loop), a different vulnerability than CAN-2003-0093.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0146">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:netpbm:netpbm:9.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netpbm:netpbm:9.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0146</vuln:cve-id>
    <vuln:published-datetime>2003-03-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:36.397-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/630433" xml:lang="en">VU#630433</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-263" xml:lang="en">DSA-263</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11463" xml:lang="en">netpbm-multiple-bo(11463)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6979" xml:lang="en">6979</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-060.html" xml:lang="en">RHSA-2003:060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104644687816522&amp;w=2" xml:lang="en">20030228 NetPBM, multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000656" xml:lang="en">CLSA-2003:656</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via "maths overflow errors" such as (1) integer signedness errors or (2) integer overflows, which lead to buffer overflows.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0147">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openpkg:openpkg"/>
        <cpe-lang:fact-ref name="cpe:/a:openpkg:openpkg:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openpkg:openpkg:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6c"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6d"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6e"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6g"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6h"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6i"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7a"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.16"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.17"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.18"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.19"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.20"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.21"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.22"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:4.01"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:4.02"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:4.03"/>
        <cpe-lang:fact-ref name="cpe:/a:stunnel:stunnel:4.04"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.17</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.20</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6h</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.13</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.15</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6g</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.8</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.12</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.9</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6b</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.18</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6c</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:4.04</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6i</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6e</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7a</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:4.02</vuln:product>
      <vuln:product>cpe:/a:openpkg:openpkg</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.14</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.16</vuln:product>
      <vuln:product>cpe:/a:openpkg:openpkg:1.2</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.10</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.19</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6d</vuln:product>
      <vuln:product>cpe:/a:openpkg:openpkg:1.1</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:4.03</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.11</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:4.0</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.7</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.22</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:3.21</vuln:product>
      <vuln:product>cpe:/a:stunnel:stunnel:4.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0147</vuln:cve-id>
    <vuln:published-datetime>2003-03-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:12:12.063-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:466" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:466" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/997481" xml:lang="en">VU#997481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/316577/30/25310/threaded" xml:lang="en">20030327 Immunix Secured OS 7+ openssl update</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded" xml:lang="en">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-102.html" xml:lang="en">RHSA-2003:102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-101.html" xml:lang="en">RHSA-2003:101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openssl.org/news/secadv_20030317.txt" xml:lang="en">http://www.openssl.org/news/secadv_20030317.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:035" xml:lang="en">MDKSA-2003:035</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-288" xml:lang="en">DSA-288</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792570615648&amp;w=2" xml:lang="en">20030317 [ADVISORY] Timing Attack on OpenSSL</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104766550528628&amp;w=2" xml:lang="en">20030313 Vulnerability in OpenSSL</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf" xml:lang="en">http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0130.html" xml:lang="en">20030313 OpenSSL Private Key Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I" xml:lang="en">20030501-01-I</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IMMUNIX</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/316577/30/25310/threaded" xml:lang="en">IMNX-2003-7+-001-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded" xml:lang="en">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.019.html" xml:lang="en">OpenPKG-SA-2003.019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200303-23.xml" xml:lang="en">GLSA-200303-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104861762028637&amp;w=2" xml:lang="en">GLSA-200303-24</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104829040921835&amp;w=2" xml:lang="en">GLSA-200303-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104819602408063&amp;w=2" xml:lang="en">20030320 [OpenPKG-SA-2003.026] OpenPKG Security Advisory (openssl)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000625" xml:lang="en">CLA-2003:625</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txt" xml:lang="en">CSSA-2003-014.0</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:466" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:466" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0148">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.0</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:3.0</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5.1</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5:sp1</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0148</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:05.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp" xml:lang="en">http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a073103-1.txt" xml:lang="en">A073103-1</vuln:reference>
    </vuln:references>
    <vuln:summary>The default installation of MSDE via McAfee ePolicy Orchestrator 2.0 through 3.0 allows attackers to execute arbitrary code via a series of steps that (1) obtain the database administrator username and encrypted password in a configuration file from the ePO server using a certain request, (2) crack the password due to weak cryptography, and (3) use the password to pass commands through xp_cmdshell.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0149">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.0</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5.1</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5:sp1</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0149</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:05.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp" xml:lang="en">http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a073103-1.txt" xml:lang="en">A073103-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in ePO agent for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request containing long parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0150">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.52"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.53"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.53a"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.54"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.54a"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:3.23.55"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mysql:mysql:3.23.53</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:3.23.52</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:3.23.55</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:3.23.54</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:3.23.54a</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:3.23.53a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0150</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:12:12.313-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:442" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:442" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/203897" xml:lang="en">VU#203897</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7052" xml:lang="en">7052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104800948128630&amp;w=2" xml:lang="en">20030318 [OpenPKG-SA-2003.022] OpenPKG Security Advisory (mysql)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11510" xml:lang="en">mysql-datadir-root-privileges(11510)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-093.html" xml:lang="en">RHSA-2003:093</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-3046.html" xml:lang="en">ESA-20030324-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-303" xml:lang="en">DSA-303</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2003-094.html" xml:lang="en">RHSA-2003:094</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104802285012750&amp;w=2" xml:lang="en">20030318 GLSA:  mysql (200303-14)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104739810523433&amp;w=2" xml:lang="en">20030310 Re: MySQL user can be changed to root</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104715840202315&amp;w=2" xml:lang="en">20030308 MySQL_user_can_be_changed_to_root?</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000743" xml:lang="en">CLA-2003:743</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:057" xml:lang="en">MDKSA-2003:057</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:442" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:442" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0151">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.0::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.0:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.0:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp3:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp4:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0.0.1:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2:express"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp1:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.0::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp3:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.0:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.0:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp3</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp4:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.0:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2:express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp4</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.0:sp1:express</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0151</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:37.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792544515384&amp;w=2" xml:lang="en">20030317 S21SEC-011 - Multiple vulnerabilities in BEA WebLogic Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792477914620&amp;w=2" xml:lang="en">20030317 SPI ADVISORY: Remote Administration of BEA WebLogic Server and Express</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.s21sec.com/en/avisos/s21sec-011-en.txt" xml:lang="en">http://www.s21sec.com/en/avisos/s21sec-011-en.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-28.jsp" xml:lang="en">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-28.jsp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7124" xml:lang="en">7124</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7122" xml:lang="en">7122</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative functions, which allows remote attackers to read arbitrary files or execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0152">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bonsai:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bonsai:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0152</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:37.443-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7162" xml:lang="en">7162</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-265" xml:lang="en">DSA-265</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in bonsai Mozilla CVS query tool allows remote attackers to execute arbitrary commands as the www-data user.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0153">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bonsai:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bonsai:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0153</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:07.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-265" xml:lang="en">DSA-265</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/9921" xml:lang="en">bonsai-path-disclosure(9921)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=102980129101054&amp;w=2" xml:lang="en">20020819 Advisory: Bonsai XSS and Physical Path Revealing Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.mozilla.org/show_bug.cgi?id=187230" xml:lang="en">http://bugzilla.mozilla.org/show_bug.cgi?id=187230</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/5517" xml:lang="en">5517</vuln:reference>
    </vuln:references>
    <vuln:summary>bonsai Mozilla CVS query tool leaks the absolute pathname of the tool in certain error messages generated by (1) cvslog.cgi, (2) cvsview2.cgi, or (3) multidiff.cgi.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0154">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bonsai:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bonsai:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0154</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:37.723-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/5516" xml:lang="en">5516</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-265" xml:lang="en">DSA-265</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://www.iss.net/security_center/static/9920.php" xml:lang="en">bonsai-error-message-xss(9920)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=102980129101054&amp;w=2" xml:lang="en">20020819 Advisory: Bonsai XSS and Physical Path Revealing Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.mozilla.org/show_bug.cgi?id=163573" xml:lang="en">http://bugzilla.mozilla.org/show_bug.cgi?id=163573</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugzilla.mozilla.org/show_bug.cgi?id=146244" xml:lang="en">http://bugzilla.mozilla.org/show_bug.cgi?id=146244</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.mozilla.org/attachment.cgi?id=95985&amp;action=view" xml:lang="en">http://bugzilla.mozilla.org/attachment.cgi?id=95985&amp;action=view</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.mozilla.org/attachment.cgi?id=95950&amp;action=view" xml:lang="en">http://bugzilla.mozilla.org/attachment.cgi?id=95950&amp;action=view</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary web script via (1) the file, root, or rev parameters to cvslog.cgi, (2) the file or root parameters to cvsblame.cgi, (3) various parameters to cvsquery.cgi, (4) the person parameter to showcheckins.cgi, (5) the module parameter to cvsqueryform.cgi, and (6) possibly other attack vectors as identified by Mozilla bug #146244.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0155">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bonsai:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bonsai:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0155</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:37.863-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7163" xml:lang="en">7163</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-265" xml:lang="en">DSA-265</vuln:reference>
    </vuln:references>
    <vuln:summary>bonsai Mozilla CVS query tool allows remote attackers to gain access to the parameters page without authentication.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0156">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cross_referencer:lxr:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cross_referencer:lxr:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:cross_referencer:lxr:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:cross_referencer:lxr:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cross_referencer:lxr:0.9.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cross_referencer:lxr:0.9</vuln:product>
      <vuln:product>cpe:/a:cross_referencer:lxr:0.3</vuln:product>
      <vuln:product>cpe:/a:cross_referencer:lxr:0.9.2</vuln:product>
      <vuln:product>cpe:/a:cross_referencer:lxr:0.9.1</vuln:product>
      <vuln:product>cpe:/a:cross_referencer:lxr:0.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0156</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:38.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7062" xml:lang="en">7062</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-264" xml:lang="en">DSA-264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104739747222492&amp;w=2" xml:lang="en">20030311 Cross-Referencing Linux vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in Cross-Referencing Linux (LXR) allows remote attackers to read arbitrary files via .. (dot dot) sequences in the v parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0157">
    <vuln:cve-id>CVE-2003-0157</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:08.460-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0138.  Reason: This candidate is a reservation duplicate of CVE-2003-0138 due to incomplete coordination.  Notes: All CVE users should reference CVE-2003-0138 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0158">
    <vuln:cve-id>CVE-2003-0158</vuln:cve-id>
    <vuln:published-datetime>2003-03-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:08.710-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0139.  Reason: This candidate is a reservation duplicate of CVE-2003-0139 due to incomplete coordination.  Notes: All CVE users should reference CVE-2003-0139 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0159">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.8.18"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.8</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.7</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.0</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.3</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.1</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.2</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.9</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.4</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.5</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.6</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.8.18</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0159</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:08.773-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:55" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:55" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7050" xml:lang="en">7050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00008.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00008.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_019_ethereal.html" xml:lang="en">SuSE-SA:2003:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-077.html" xml:lang="en">RHSA-2003:077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:051" xml:lang="en">MDKSA-2003:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104741640924709&amp;w=2" xml:lang="en">20030309 GLSA:  ethereal (200303-10)</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:55" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:55" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in the NTLMSSP code for Ethereal 0.9.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0160">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0160</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:08.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:614" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:614" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/mailarchive/forum.php?thread_id=1641953&amp;forum_id=1988" xml:lang="en">http://sourceforge.net/mailarchive/forum.php?thread_id=1641953&amp;forum_id=1988</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-112.html" xml:lang="en">RHSA-2003:112</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:614" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:614" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.2.11 allow remote attackers to inject arbitrary HTML code and steal information from a client's web browser.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0161">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.10"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.11.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.7"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12.8"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12:beta10"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12:beta12"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12:beta16"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.12:beta7"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail_switch:3.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0b"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0d"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0d_pk9_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f_pk6_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f_pk7_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0g"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0g_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0_pk4_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0_pk4_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0a"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0a_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0f"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk4_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk5_bl19"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk6_bl20"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk1_bl1"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk2_bl2"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk3_bl3"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1b"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1b_pk1_bl1"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.08"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.09"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.16"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.26"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.30"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.34"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.22"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux_series_700:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux_series_800:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:sis"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0:x86_update_2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2.4</vuln:product>
      <vuln:product>cpe:/o:hp:sis</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1b_pk1_bl1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:3.0.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.9.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0:x86_update_2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12:beta5</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:3.0.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:2.6.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2.2</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.08</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.4</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.9.2</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f_pk6_bl17</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.22</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.6</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk1_bl1</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.26</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk5_bl19</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.16</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12:beta16</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.30</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1.5</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:3.0.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.0</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.10</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:3.0</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.10.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:2.6.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:3.0.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0b</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f_pk7_bl18</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk3_bl17</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12:beta7</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0_pk4_bl17</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0d</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12:beta10</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.9.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:3.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::ppc</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.09</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk6_bl20</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.7</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:3.0.2</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.20</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.34</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux_series_800:10.20</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.0</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:2.6</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2.1</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.10.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12:beta12</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0d_pk9_bl17</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0f</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.6</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.9.1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0g_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2.5</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux_series_700:10.20</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0g</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.0.4</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0_pk4_bl18</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1b</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1.2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:3.0.2</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0a_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk4_bl18</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.11.3</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk3_bl3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.1.4</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail_switch:2.2.3</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0a</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk2_bl2</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.12.8</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0161</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-05-25T00:18:16.750-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-12.html" xml:lang="en">CA-2003-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/897604" xml:lang="en">VU#897604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7230" xml:lang="en">7230</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-120.html" xml:lang="en">RHSA-2003:120</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IMMUNIX</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/317135/30/25220/threaded" xml:lang="en">IMNX-2003-7+-002-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-121.html" xml:lang="en">RHSA-2003:121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-290" xml:lang="en">DSA-290</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-278" xml:lang="en">DSA-278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1001088.1-1" xml:lang="en">1001088</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104897487512238&amp;w=2" xml:lang="en">20030329 Sendmail: -1 gone wild</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-March/004295.html" xml:lang="en">20030329 Sendmail: -1 gone wild</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00028.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00028.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030401-01-P" xml:lang="en">20030401-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.11/SCOSA-2004.11.txt" xml:lang="en">SCOSA-2004.11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:07.sendmail.asc" xml:lang="en">FreeBSD-SA-03:07</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-016.0.txt" xml:lang="en">CSSA-2003-016.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IMMUNIX</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/317135/30/25220/threaded" xml:lang="en">IMNX-2003-7+-002-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/316961/30/25250/threaded" xml:lang="en">20030331 GLSA: sendmail (200303-27)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/321997" xml:lang="en">20030520 [Fwd: 127 Research and Development: 127 Day!]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200303-27.xml" xml:lang="en">GLSA-200303-27</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52700-1" xml:lang="en">52700</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52620-1" xml:lang="en">52620</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104914999806315&amp;w=2" xml:lang="en">20030330 [OpenPKG-SA-2003.027] OpenPKG Security Advisory (sendmail)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104896621106790&amp;w=2" xml:lang="en">20030329 sendmail 8.12.9 available</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000614" xml:lang="en">CLA-2003:614</vuln:reference>
    </vuln:references>
    <vuln:summary>The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0162">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ecartis:ecartis:1.0.0_snapshot_2002-10-13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ecartis:ecartis:1.0.0_snapshot_2002-10-13</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0162</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:38.973-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6971" xml:lang="en">6971</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11431" xml:lang="en">ecartis-password-reset(11431)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-271" xml:lang="en">DSA-271</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104673407728323&amp;w=2" xml:lang="en">20030303 Re: Ecardis Password Reseting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104636153214262&amp;w=2" xml:lang="en">20030227 Ecardis Password Reseting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Ecartis 1.0.0 (formerly listar) before snapshot 20030227 allows remote attackers to reset passwords of other users and gain privileges by modifying hidden form fields in the HTML page.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0163">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gaim-encryption:gaim-encryption:1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:gaim-encryption:gaim-encryption:1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:gaim-encryption:gaim-encryption:1.15"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gaim-encryption:gaim-encryption:1.15</vuln:product>
      <vuln:product>cpe:/a:gaim-encryption:gaim-encryption:1.13</vuln:product>
      <vuln:product>cpe:/a:gaim-encryption:gaim-encryption:1.14</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0163</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:39.130-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7182" xml:lang="en">7182</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.rapid7.com/advisories/R7-0013.html" xml:lang="en">http://www.rapid7.com/advisories/R7-0013.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105013281120352&amp;w=2" xml:lang="en">20030412 R7-0013: Heap Corruption in Gaim-Encryption Plugin</vuln:reference>
    </vuln:references>
    <vuln:summary>decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a zero byte.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0165">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnome:eog:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:eog:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:eog:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:eog:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:eog:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:eog:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:eog:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:eog:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:eog:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:eog:2.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnome:eog:1.1.1</vuln:product>
      <vuln:product>cpe:/a:gnome:eog:1.0.0</vuln:product>
      <vuln:product>cpe:/a:gnome:eog:1.1.3</vuln:product>
      <vuln:product>cpe:/a:gnome:eog:1.0.2</vuln:product>
      <vuln:product>cpe:/a:gnome:eog:1.1.2</vuln:product>
      <vuln:product>cpe:/a:gnome:eog:1.0.4</vuln:product>
      <vuln:product>cpe:/a:gnome:eog:1.0.3</vuln:product>
      <vuln:product>cpe:/a:gnome:eog:2.2.0</vuln:product>
      <vuln:product>cpe:/a:gnome:eog:1.1.4</vuln:product>
      <vuln:product>cpe:/a:gnome:eog:1.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0165</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:09.133-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:52" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:52" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/363001" xml:lang="en">VU#363001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7121" xml:lang="en">7121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-128.html" xml:lang="en">RHSA-2003:128</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887189724146&amp;w=2" xml:lang="en">20030328 CORE-2003-0304-03: Vulnerability in GNOME's Eye of Gnome</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0157.html" xml:lang="en">20030328 Vulnerability in GNOME's Eye of Gnome</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:048" xml:lang="en">MDKSA-2003:048</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=312&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=312&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:52" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:52" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0166">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0166</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:09.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7198" xml:lang="en">7198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7197" xml:lang="en">7197</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104869828526885&amp;w=2" xml:lang="en">20030326 @(#)Mordred Labs advisory - Integer overflow in PHP memory allocator</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104931415307111&amp;w=2" xml:lang="en">20030402 Inaccurate Reports Concerning PHP Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878100719467&amp;w=2" xml:lang="en">20030327 RE: FUD-ALARM: @(#)Mordred Labs advisory - Integer overflow in PHP memory allocator</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000691" xml:lang="en">CLSA-2003:691</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2) socket_recvfrom, and possibly other functions.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0167">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.12.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.22"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.24"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.25"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.27"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.28"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mutt:mutt:1.3.24</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.12</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.25</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.17</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.16</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.12.1</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.22</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.28</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.27</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0167</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:39.630-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7229" xml:lang="en">7229</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-274" xml:lang="en">DSA-274</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-300" xml:lang="en">DSA-300</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple off-by-one buffer overflows in the IMAP capability for Mutt 1.3.28 and earlier, and Balsa 1.2.4 and earlier, allow a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a specially crafted mail folder, a different vulnerability than CVE-2003-0140.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0168">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:6.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0168</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:12:13.643-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/112553" xml:lang="en">VU#112553</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/317141/30/25220/threaded" xml:lang="en">20030401 Fwd: QuickTime 6.1 for Windows is available</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/advisory/03.31.03.txt" xml:lang="en">http://www.idefense.com/advisory/03.31.03.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00027.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00027.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0166.html" xml:lang="en">20030331 iDEFENSE Security Advisory 03.31.03: Buffer Overflow in Windows QuickTime Player</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11671" xml:lang="en">quicktime-url-bo(11671)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7247" xml:lang="en">7247</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/317148/30/25220/threaded" xml:lang="en">20030401 iDEFENSE Security Advisory 03.31.03: Buffer Overflow in Windows QuickTime Player</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/317141/30/25220/threaded" xml:lang="en">20030401 Fwd: QuickTime 6.1 for Windows is available</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/10561" xml:lang="en">10561</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Apple QuickTime Player 5.x and 6.0 for Windows allows remote attackers to execute arbitrary code via a long QuickTime URL.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0169">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hp:instant_toptools:5.04"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:instant_toptools:5.04</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0169</vuln:cve-id>
    <vuln:published-datetime>2003-04-11T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:39.910-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7246" xml:lang="en">7246</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0164.html" xml:lang="en">20030331 [DDI-1012] Malformed request causes denial of service in HP Instant TopTools</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104914959705949&amp;w=2" xml:lang="en">20030331 [DDI-1012] Malformed request causes denial of service in HP Instant TopTools</vuln:reference>
    </vuln:references>
    <vuln:summary>hpnst.exe in the GoAhead-Webs webserver for HP Instant TopTools before 5.55 allows remote attackers to cause a denial of service (CPU consumption) via a request to hpnst.exe that calls itself, which causes an infinite loop.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0170">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0170</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:40.037-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11823" xml:lang="en">aix-ftpd-gain-access(11823)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7346" xml:lang="en">7346</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=isg1IY42424" xml:lang="en">IY42424</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IBM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2003.0469.1" xml:lang="en">MSS-OAR-E01-2003.0469.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/4878" xml:lang="en">4878</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0171">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0171</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:10.087-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2003/a041003-1.txt" xml:lang="en">A041003-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00028.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00028.html</vuln:reference>
    </vuln:references>
    <vuln:summary>DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0172">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0172</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:40.397-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7210" xml:lang="en">7210</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878149020152&amp;w=2" xml:lang="en">20030327 @(#)Mordred Labs advisory - PHP for Win32: buffer overflow in openlog() function</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11637" xml:lang="en">php-openlog-stack-bo(11637)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/385238" xml:lang="en">20041222 PHP v4.3.x exploit for Windows.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/316583" xml:lang="en">20030327 Re: @(#)Mordred Labs advisory - PHP for Win32: buffer overflow in openlog() function</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/2113" xml:lang="en">2113</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104931415307111&amp;w=2" xml:lang="en">20030402 Inaccurate Reports Concerning PHP Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote attackers to cause a crash and possibly execute arbitrary code via a long filename argument.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0173">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xfsdump:xfsdump:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfsdump:xfsdump:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xfsdump:xfsdump:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:xfsdump:xfsdump:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:xfsdump:xfsdump:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:xfsdump:xfsdump:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9m"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5.4m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16m</vuln:product>
      <vuln:product>cpe:/a:xfsdump:xfsdump:2.0.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11m</vuln:product>
      <vuln:product>cpe:/a:xfsdump:xfsdump:2.0.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/a:xfsdump:xfsdump:2.0.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6m</vuln:product>
      <vuln:product>cpe:/a:xfsdump:xfsdump:2.0.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/a:xfsdump:xfsdump:2.0.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3m</vuln:product>
      <vuln:product>cpe:/a:xfsdump:xfsdump:2.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0173</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:10.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/111673" xml:lang="en">VU#111673</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-283" xml:lang="en">DSA-283</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030404-01-P" xml:lang="en">20030404-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:047" xml:lang="en">MDKSA-2003:047</vuln:reference>
    </vuln:references>
    <vuln:summary>xfsdq in xfsdump does not create quota information files securely, which allows local users to gain root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0174">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9m"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5.4m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0174</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:40.833-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7442" xml:lang="en">7442</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030407-01-P" xml:lang="en">20030407-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11860" xml:lang="en">irix-ldap-authentication-bypass(11860)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-084.shtml" xml:lang="en">N-084</vuln:reference>
    </vuln:references>
    <vuln:summary>The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0175">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9m"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5.4m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0175</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:41.097-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/142228" xml:lang="en">VU#142228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/12241" xml:lang="en">irix-piocswatch-ioctl-dos(12241)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7868" xml:lang="en">7868</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030603-01-P" xml:lang="en">20030603-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008770" xml:lang="en">1008770</vuln:reference>
    </vuln:references>
    <vuln:summary>SGI IRIX before 6.5.21 allows local users to cause a denial of service (kernel panic) via a certain call to the PIOCSWATCH ioctl.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0176">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0176</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:41.363-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030701-01-P" xml:lang="en">20030701-01-P</vuln:reference>
    </vuln:references>
    <vuln:summary>The Name Service Daemon (nsd), when running on an NIS master on SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows remote attackers to cause a denial of service (crash) via a UDP port scan.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0177">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0177</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:41.550-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030701-01-P" xml:lang="en">20030701-01-P</vuln:reference>
    </vuln:references>
    <vuln:summary>SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, does not follow "-" entries in the /etc/group file, which may cause subsequent group membership entries to be processed inadvertently.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0178">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0178</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:41.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/772817" xml:lang="en">VU#772817</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/542873" xml:lang="en">VU#542873</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/206361" xml:lang="en">VU#206361</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-11.html" xml:lang="en">CA-2003-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6871" xml:lang="en">6871</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550063431461&amp;w=2" xml:lang="en">20030217 Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11337" xml:lang="en">lotus-domino-hostname-bo(11337)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11336" xml:lang="en">lotus-domino-inotes-bo(11336)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6870" xml:lang="en">6870</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/lotus-inotesoflow.txt" xml:lang="en">http://www.nextgenss.com/advisories/lotus-inotesoflow.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/lotus-hostlocbo.txt" xml:lang="en">http://www.nextgenss.com/advisories/lotus-hostlocbo.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-065.shtml" xml:lang="en">N-065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558778331387&amp;w=2" xml:lang="en">20030217 Domino Advisories UPDATE</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558777531350&amp;w=2" xml:lang="en">20030217 Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558777331345&amp;w=2" xml:lang="en">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550335103136&amp;w=2" xml:lang="en">20030217 Domino Advisories UPDATE</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550063431463&amp;w=2" xml:lang="en">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.html" xml:lang="en">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0081.html" xml:lang="en">20030217 Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0080.html" xml:lang="en">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the PresetFields parameter for iNotes, or (3) a long Host header, which is inserted into a long Location header and used during a redirect operation.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0179">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes_client:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes_client:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0179</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:41.897-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/571297" xml:lang="en">VU#571297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-11.html" xml:lang="en">CA-2003-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6872" xml:lang="en">6872</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550124032513&amp;w=2" xml:lang="en">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11339" xml:lang="en">lotus-notes-activex-bo(11339)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/lotus-inotesclientaxbo.txt" xml:lang="en">http://www.nextgenss.com/advisories/lotus-inotesclientaxbo.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-065.shtml" xml:lang="en">N-065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg21104543" xml:lang="en">http://www-1.ibm.com/support/docview.wss?uid=swg21104543</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558778331387&amp;w=2" xml:lang="en">20030217 Domino Advisories UPDATE</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558778131373&amp;w=2" xml:lang="en">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550335103136&amp;w=2" xml:lang="en">20030217 Domino Advisories UPDATE</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.html" xml:lang="en">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0180">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0180</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:12:14.783-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/355169" xml:lang="en">VU#355169</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-11.html" xml:lang="en">CA-2003-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/lotus-60dos.txt" xml:lang="en">http://www.nextgenss.com/advisories/lotus-60dos.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11360" xml:lang="en">lotus-incomplete-post-dos(11360)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6951" xml:lang="en">6951</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-065.shtml" xml:lang="en">N-065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg21104528" xml:lang="en">http://www-1.ibm.com/support/docview.wss?uid=swg21104528</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0086.html" xml:lang="en">20030218 More Lotus Domino Advisories</vuln:reference>
    </vuln:references>
    <vuln:summary>Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via an incomplete POST request, as demonstrated using the h_PageUI form.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0181">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0181</vuln:cve-id>
    <vuln:published-datetime>2003-04-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:42.193-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-11.html" xml:lang="en">CA-2003-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/lotus-60dos.txt" xml:lang="en">http://www.nextgenss.com/advisories/lotus-60dos.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11361" xml:lang="en">lotus-invalid-field-dos(11361)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6951" xml:lang="en">6951</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg21104528" xml:lang="en">http://www-1.ibm.com/support/docview.wss?uid=swg21104528</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0086.html" xml:lang="en">20030218 More Lotus Domino Advisories</vuln:reference>
    </vuln:references>
    <vuln:summary>Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a "Fictionary Value Field POST request" as demonstrated using the s_Validation form with a long, unknown parameter name.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0187">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0187</vuln:cve-id>
    <vuln:published-datetime>2003-08-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:10.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:260" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:260" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105986028426824&amp;w=2" xml:lang="en">20030802 [SECURITY] Netfilter Security Advisory: Conntrack list_del() DoS</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:260" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:260" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The connection tracking core of Netfilter for Linux 2.4.20, with CONFIG_IP_NF_CONNTRACK enabled or the ip_conntrack module loaded, allows remote attackers to cause a denial of service (resource consumption) due to an inconsistency with Linux 2.4.20's support of linked lists, which causes Netfilter to fail to identify connections with an UNCONFIRMED status and use large timeouts.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0188">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:lv:lv:4.49.1"/>
        <cpe-lang:fact-ref name="cpe:/a:lv:lv:4.49.2"/>
        <cpe-lang:fact-ref name="cpe:/a:lv:lv:4.49.3"/>
        <cpe-lang:fact-ref name="cpe:/a:lv:lv:4.49.4"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:lv:4.49.4-1::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:lv:4.49.4-3::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:lv:4.49.4-7::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:lv:4.49.4-9::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.3"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:9.0::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:redhat:lv:4.49.4-7::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:lv:4.49.4-3::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:9.0::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.3</vuln:product>
      <vuln:product>cpe:/a:redhat:lv:4.49.4-1::i386</vuln:product>
      <vuln:product>cpe:/a:lv:lv:4.49.3</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:8.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.1</vuln:product>
      <vuln:product>cpe:/a:lv:lv:4.49.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.2</vuln:product>
      <vuln:product>cpe:/a:redhat:lv:4.49.4-9::i386</vuln:product>
      <vuln:product>cpe:/a:lv:lv:4.49.4</vuln:product>
      <vuln:product>cpe:/a:lv:lv:4.49.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0188</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:11.023-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:430" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:430" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-169.html" xml:lang="en">RHSA-2003:169</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-304" xml:lang="en">DSA-304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-35.txt" xml:lang="en">TLSA-2003-35</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-167.html" xml:lang="en">RHSA-2003:167</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:430" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:430" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other directories.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0189">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.44"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.45"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.44</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.45</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0189</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:42.647-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/479268" xml:lang="en">VU#479268</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-186.html" xml:lang="en">RHSA-2003:186</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.apache.org/dist/httpd/Announcement2.html" xml:lang="en">http://www.apache.org/dist/httpd/Announcement2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105418115512559&amp;w=2" xml:lang="en">20030528 [SECURITY] [ANNOUNCE] Apache 2.0.46 released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/12091" xml:lang="en">apache-aprpasswordvalidate-dos(12091)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7725" xml:lang="en">7725</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8881" xml:lang="en">8881</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000661" xml:lang="en">CLA-2003:661</vuln:reference>
    </vuln:references>
    <vuln:summary>The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0190">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.4p1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.6.1p1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openbsd:openssh:3.6.1p1</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:3.4p1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0190</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:12:15.470-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:445" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:445" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7467" xml:lang="en">7467</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105172058404810&amp;w=2" xml:lang="en">20030430 OpenSSH/PAM timing attack allows remote users identification</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-31.txt" xml:lang="en">TLSA-2003-31</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-224.html" xml:lang="en">RHSA-2003:224</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-222.html" xml:lang="en">RHSA-2003:222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106018677302607&amp;w=2" xml:lang="en">20030806 [OpenPKG-SA-2003.035] OpenPKG Security Advisory (openssh)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004815.html" xml:lang="en">20030430 OpenSSH/PAM timing attack allows remote users identification</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://lab.mediaservice.net/advisory/2003-01-openssh.txt" xml:lang="en">http://lab.mediaservice.net/advisory/2003-01-openssh.txt</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:445" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:445" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0192">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.35"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.44"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.45"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.46"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:2.0.28</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.35</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.45</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.44</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.46</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.32</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0192</vuln:cve-id>
    <vuln:published-datetime>2003-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:11.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:169" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:169" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-240.html" xml:lang="en">RHSA-2003:240</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105776593602600&amp;w=2" xml:lang="en">20030709 [ANNOUNCE][SECURITY] Apache 2.0.47 released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-243.html" xml:lang="en">RHSA-2003:243</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.6/SCOSA-2004.6.txt" xml:lang="en">SCOSA-2004.6</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-244.html" xml:lang="en">RHSA-2003:244</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:075" xml:lang="en">MDKSA-2003:075</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:169" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:169" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0193">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:catdoc:catdoc:0.91"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:catdoc:catdoc:0.91</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0193</vuln:cve-id>
    <vuln:published-datetime>2004-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:43.130-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-575" xml:lang="en">DSA-575</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/16335" xml:lang="en">catdoc-xlsview-symlink(16335)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11560" xml:lang="en">11560</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/11193" xml:lang="en">11193</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13022/" xml:lang="en">13022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13021/" xml:lang="en">13021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=183525" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=183525</vuln:reference>
    </vuln:references>
    <vuln:summary>msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").</vuln:summary>
  </entry>
  <entry id="CVE-2003-0194">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:redhat:tcpdump:3.4-39::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:tcpdump:3.6.2-12::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:tcpdump:3.6.2-9::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:tcpdump:3.6.2-9::ia64"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:tcpdump:3.6.3-3::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:tcpdump:3.7.2-1::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.3"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:9.0::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:linux:9.0::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.3</vuln:product>
      <vuln:product>cpe:/a:redhat:tcpdump:3.7.2-1::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:8.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.1</vuln:product>
      <vuln:product>cpe:/a:redhat:tcpdump:3.6.3-3::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:tcpdump:3.6.2-9::i386</vuln:product>
      <vuln:product>cpe:/a:redhat:tcpdump:3.4-39::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.2</vuln:product>
      <vuln:product>cpe:/a:redhat:tcpdump:3.6.2-9::ia64</vuln:product>
      <vuln:product>cpe:/a:redhat:tcpdump:3.6.2-12::i386</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0194</vuln:cve-id>
    <vuln:published-datetime>2003-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:43.270-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-174.html" xml:lang="en">RHSA-2003:174</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-151.html" xml:lang="en">RHSA-2003:151</vuln:reference>
    </vuln:references>
    <vuln:summary>tcpdump does not properly drop privileges to the pcap user when starting up.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0195">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:8.1"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:slackware:slackware_linux:9.0</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:8.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0195</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:12.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-171.html" xml:lang="en">RHSA-2003:171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-317" xml:lang="en">DSA-317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/TLSA-2003-33.txt" xml:lang="en">TLSA-2003-33</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_028.html" xml:lang="en">SuSE-SA:2003:028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7637" xml:lang="en">7637</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:062" xml:lang="en">MDKSA-2003:062</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105427288724449&amp;w=2" xml:lang="en">20030529 [slackware-security]  CUPS DoS vulnerability fixed (SSA:2003-149-01)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000678" xml:lang="en">CLSA-2003:678</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0196">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:samba-tng:samba-tng:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba-tng:samba-tng:0.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.1a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.3a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.7a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0b"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0d"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0d_pk9_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f_pk6_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f_pk7_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0g"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0g_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0_pk4_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0_pk4_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0a"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0a_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0f"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk4_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk5_bl19"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk6_bl20"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk1_bl1"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk2_bl2"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk3_bl3"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1b"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1b_pk1_bl1"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.04"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.22"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.05"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.06"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.07"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.08"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.08.01"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.09"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.09.01"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.09.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.7a</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1b_pk1_bl1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.0a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.8</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0d</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.09.01</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.1a</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.05</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::ppc</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.0</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk6_bl20</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.4</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.04</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.20</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f_pk6_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.09.02</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.8</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.22</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.07</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.3a</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk1_bl1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.6</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk5_bl19</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0d_pk9_bl17</vuln:product>
      <vuln:product>cpe:/a:samba-tng:samba-tng:0.3.1</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.09</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.06</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0f</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.08.01</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0g_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.7</vuln:product>
      <vuln:product>cpe:/a:samba-tng:samba-tng:0.3</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0g</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0_pk4_bl18</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1b</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0b</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f_pk7_bl18</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0a_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk4_bl18</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk3_bl3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.2</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.08</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.5</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0a</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk2_bl2</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0_pk4_bl17</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0196</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:12.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:564" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:564" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-137.html" xml:lang="en">RHSA-2003:137</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-280" xml:lang="en">DSA-280</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104973186901597&amp;w=2" xml:lang="en">20030407 [OpenPKG-SA-2003.028] OpenPKG Security Advisory (samba)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:044" xml:lang="en">MDKSA-2003:044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104974612519064&amp;w=2" xml:lang="en">20030407 Immunix Secured OS 7+ samba update</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:564" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:564" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0197">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:borland_software:interbase:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:borland_software:interbase:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:borland_software:interbase:6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:firebirdsql:firebird:1.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:borland_software:interbase:6.5</vuln:product>
      <vuln:product>cpe:/a:borland_software:interbase:6.4</vuln:product>
      <vuln:product>cpe:/a:firebirdsql:firebird:1.0.2</vuln:product>
      <vuln:product>cpe:/a:borland_software:interbase:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0197</vuln:cve-id>
    <vuln:published-datetime>2003-04-11T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:13.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.secnetops.com/research/advisories/SRT2003-04-03-1300.txt" xml:lang="en">http://www.secnetops.com/research/advisories/SRT2003-04-03-1300.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104940730819887&amp;w=2" xml:lang="en">20030403 SRT2003-04-03-1300 - Interbase ISC_LOCK_ENV overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0003.html" xml:lang="en">20030403 SRT2003-04-03-1300 - Interbase ISC_LOCK_ENV overflow</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow gds_lock_mgr of Interbase Database 6.x allows local users to gain privileges via a long ISC_LOCK_ENV environment variable (INTERBASE_LOCK).</vuln:summary>
  </entry>
  <entry id="CVE-2003-0198">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0198</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:13.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00028.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00028.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0201">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:samba-tng:samba-tng:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba-tng:samba-tng:0.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.1a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.3a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.7a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.2.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0b"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0d"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0d_pk9_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f_pk6_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0f_pk7_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0g"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:4.0g_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0_pk4_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0_pk4_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0a"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0a_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.0f"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk3_bl17"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk4_bl18"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk5_bl19"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1_pk6_bl20"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk1_bl1"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk2_bl2"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1a_pk3_bl3"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1b"/>
        <cpe-lang:fact-ref name="cpe:/o:compaq:tru64:5.1b_pk1_bl1"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.04"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.22"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0:x86_update_2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.05"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.06"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.07"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.08"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.08.01"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.09"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.09.01"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:cifs-9000_server:a.01.09.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.7a</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1b_pk1_bl1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.0a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.8</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0d</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.09.01</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0:x86_update_2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.1a</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.05</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::ppc</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.0</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk6_bl20</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.4</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.04</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.20</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f_pk6_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.09.02</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.8</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.22</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.07</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.3a</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk1_bl1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.6</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk5_bl19</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0d_pk9_bl17</vuln:product>
      <vuln:product>cpe:/a:samba-tng:samba-tng:0.3.1</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.09</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.06</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0f</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.08.01</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0g_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.2.7</vuln:product>
      <vuln:product>cpe:/a:samba-tng:samba-tng:0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0g</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0_pk4_bl18</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1b</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0b</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:4.0f_pk7_bl18</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0a_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk3_bl17</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1_pk4_bl18</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk3_bl3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.2</vuln:product>
      <vuln:product>cpe:/a:hp:cifs-9000_server:a.01.08</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.5</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0a</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.1a_pk2_bl2</vuln:product>
      <vuln:product>cpe:/o:compaq:tru64:5.0_pk4_bl17</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0201</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:14.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:567" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:567" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2163" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2163" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/267873" xml:lang="en">VU#267873</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7294" xml:lang="en">7294</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-280" xml:lang="en">DSA-280</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104972664226781&amp;w=2" xml:lang="en">20030407 [DDI-1013] Buffer Overflow in Samba allows remote root compromise</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-137.html" xml:lang="en">RHSA-2003:137</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_025_samba.html" xml:lang="en">SuSE-SA:2003:025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitaldefense.net/labs/advisories/DDI-1013.txt" xml:lang="en">http://www.digitaldefense.net/labs/advisories/DDI-1013.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20030403-01-P" xml:lang="en">20030403-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:044" xml:lang="en">MDKSA-2003:044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104994564212488&amp;w=2" xml:lang="en">20030409 GLSA:  samba (200304-02)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104981682014565&amp;w=2" xml:lang="en">20030408 [Sorcerer-spells] SAMBA--SORCERER2003-04-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104974612519064&amp;w=2" xml:lang="en">20030407 Immunix Secured OS 7+ samba update</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000624" xml:lang="en">CLA-2003:624</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:567" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:567" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2163" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2163" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0202">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:brian_renaud:metrics:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:brian_renaud:metrics:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0202</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:44.550-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-279" xml:lang="en">DSA-279</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11734" xml:lang="en">metrics-tmpfile-symlink(11734)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7293" xml:lang="en">7293</vuln:reference>
    </vuln:references>
    <vuln:summary>The (1) halstead and (2) gather_stats scripts in metrics 1.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0203">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:moxftp:moxftp:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:xftp:xftp:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:moxftp:moxftp:2.2</vuln:product>
      <vuln:product>cpe:/a:xftp:xftp:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0203</vuln:cve-id>
    <vuln:published-datetime>2003-04-11T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:12:16.407-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/6921" xml:lang="en">6921</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11399" xml:lang="en">moxftp-welcome-banner-bo(11399)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-281" xml:lang="en">DSA-281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610380126860&amp;w=2" xml:lang="en">20030223 moxftp arbitrary code execution poc/advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006156" xml:lang="en">1006156</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2003-02/0338.html" xml:lang="en">20030223 moxftp arbitrary code execution poc/advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8136" xml:lang="en">8136</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in moxftp 2.2 and earlier allows remote malicious FTP servers to execute arbitrary code via a long FTP banner.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0204">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.3a"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.5a"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:kde:kde:3.1.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.4</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.3a</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.3</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.5a</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.2.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.2.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.0</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.5</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.1.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.1.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0204</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:14.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kde.org/info/security/advisory-20030409-1.txt" xml:lang="en">http://www.kde.org/info/security/advisory-20030409-1.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-284" xml:lang="en">DSA-284</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-002.html" xml:lang="en">RHSA-2003:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-296" xml:lang="en">DSA-296</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-293" xml:lang="en">DSA-293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.kde.org/show_bug.cgi?id=56808" xml:lang="en">http://bugs.kde.org/show_bug.cgi?id=56808</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.kde.org/show_bug.cgi?id=53343" xml:lang="en">http://bugs.kde.org/show_bug.cgi?id=53343</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:049" xml:lang="en">MDKSA-2003:049</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105034222521369&amp;w=2" xml:lang="en">20030414 GLSA:  kde-2.x (200304-05.1)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105017403010459&amp;w=2" xml:lang="en">20030412 [Sorcerer-spells] KDE-SORCERER2003-04-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105012994719099&amp;w=2" xml:lang="en">20030411 GLSA:  kde-2.x (200304-05)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105001557020141&amp;w=2" xml:lang="en">20030410 GLSA:  kde-3.x (200304-04)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000747" xml:lang="en">CLA-2003:747</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000668" xml:lang="en">CLA-2003:668</vuln:reference>
    </vuln:references>
    <vuln:summary>KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0205">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gkrellm_newsticker:gkrellm_newsticker:0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gkrellm_newsticker:gkrellm_newsticker:0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0205</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:14.930-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-294" xml:lang="en">DSA-294</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105111327000755&amp;w=2" xml:lang="en">20030423 Security problems in gkrellm-newsticker</vuln:reference>
    </vuln:references>
    <vuln:summary>gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the ticker title of a URI.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0206">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gkrellm_newsticker:gkrellm_newsticker:0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gkrellm_newsticker:gkrellm_newsticker:0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0206</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:14.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-294" xml:lang="en">DSA-294</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105111327000755&amp;w=2" xml:lang="en">20030423 Security problems in gkrellm-newsticker</vuln:reference>
    </vuln:references>
    <vuln:summary>gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to cause a denial of service (crash) via (1) link or (2) title elements that contain multiple lines.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0207">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gs-common:gs-common:0.3.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gs-common:gs-common:0.3.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0207</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:15.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-286" xml:lang="en">DSA-286</vuln:reference>
    </vuln:references>
    <vuln:summary>ps2epsi creates insecure temporary files when calling ghostscript, which allows local attackers to overwrite arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0208">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:macromedia:flash</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0208</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:45.457-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/securitynews/5XP0B0U9PE.html" xml:lang="en">http://www.securiteam.com/securitynews/5XP0B0U9PE.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.macromedia.com/support/flash/ts/documents/clicktag_security.htm" xml:lang="en">http://www.macromedia.com/support/flash/ts/documents/clicktag_security.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004514.html" xml:lang="en">20030413 Misuse of Macromedia Flash Ads clickTAG Option May Lead to Privacy Breach</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105033712615013&amp;w=2" xml:lang="en">20030413 Misuse of Macromedia Flash Ads clickTAG Option May Lead to Privacy Breach</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Macromedia Flash ad user tracking capability allows remote attackers to insert arbitrary Javascript via the clickTAG field.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0209">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:smoothwall:smoothwall:2.0_beta_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sourcefire:snort:1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:sourcefire:snort:1.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sourcefire:snort:1.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sourcefire:snort:1.8.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sourcefire:snort:1.8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sourcefire:snort:1.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sourcefire:snort:1.8.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sourcefire:snort:1.8.7"/>
        <cpe-lang:fact-ref name="cpe:/a:sourcefire:snort:1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:sourcefire:snort:1.9.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sourcefire:snort:1.9</vuln:product>
      <vuln:product>cpe:/a:sourcefire:snort:1.8.3</vuln:product>
      <vuln:product>cpe:/a:sourcefire:snort:1.8.6</vuln:product>
      <vuln:product>cpe:/a:sourcefire:snort:1.9.1</vuln:product>
      <vuln:product>cpe:/a:sourcefire:snort:1.8.7</vuln:product>
      <vuln:product>cpe:/a:sourcefire:snort:1.8.5</vuln:product>
      <vuln:product>cpe:/a:sourcefire:snort:1.8</vuln:product>
      <vuln:product>cpe:/a:sourcefire:snort:1.8.2</vuln:product>
      <vuln:product>cpe:/a:sourcefire:snort:1.8.1</vuln:product>
      <vuln:product>cpe:/a:smoothwall:smoothwall:2.0_beta_4</vuln:product>
      <vuln:product>cpe:/a:sourcefire:snort:1.8.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0209</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:15.603-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/139129" xml:lang="en">VU#139129</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2003-13.html" xml:lang="en">CA-2003-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7178" xml:lang="en">7178</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-297" xml:lang="en">DSA-297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=313&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=313&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105172790914107&amp;w=2" xml:lang="en">ESA-20030430-013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154530427824&amp;w=2" xml:lang="en">20030428 GLSA:  snort (200304-06)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105111217731583&amp;w=2" xml:lang="en">20030423 Snort &lt;=1.9.1 exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105103586927007&amp;w=2" xml:lang="en">20030422 GLSA:  snort (200304-05)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105043563016235&amp;w=2" xml:lang="en">20030415 CORE-2003-0307: Snort TCP Stream Reassembly Integer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:052" xml:lang="en">MDKSA-2003:052</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, which enable a heap-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0210">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:3.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:3.0.1</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:2.3</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:3.1.1</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:3.0</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:2.4</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:2.6</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:2.6.4</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:2.6.3</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:2.1</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:2.6.2</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:2.5</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:3.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0210</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:15.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/697049" xml:lang="en">VU#697049</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20030423-ACS.shtml" xml:lang="en">20030423 Cisco Secure Access Control Server for Windows Admin Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105120066126196&amp;w=2" xml:lang="en">20030424 NSFOCUS SA2003-04 : Remote Buffer Overflow Vulnerability in Web Management Interface of Cisco Secure ACS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105118056332344&amp;w=2" xml:lang="en">20030424 NSFOCUS SA2003-04 : Remote Buffer Overflow Vulnerability in Web Management Interface of Cisco Secure ACS</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the administration service (CSAdmin) for Cisco Secure ACS before 3.1.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long user parameter to port 2002.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0211">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:xinetd:xinetd:2.3.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.4</vuln:product>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.0</vuln:product>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.3</vuln:product>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.6</vuln:product>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.2</vuln:product>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.10</vuln:product>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.8</vuln:product>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.7</vuln:product>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.1</vuln:product>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.9</vuln:product>
      <vuln:product>cpe:/a:xinetd:xinetd:2.3.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0211</vuln:cve-id>
    <vuln:published-datetime>2003-05-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:15.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:657" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:657" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105068673220605&amp;w=2" xml:lang="en">20030418 Xinetd 2.3.10 Memory Leaks</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2003-160.html" xml:lang="en">RHSA-2003:160</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=88537" xml:lang="en">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=88537</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2003:056" xml:lang="en">MDKSA-2003:056</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000782" xml:lang="en">CLA-2003:782</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:657" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:657" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0212">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rinetd:rinetd:0.52"/>
        <cpe-lang:fact-ref name="cpe:/a:rinetd:rinetd:0.61"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rinetd:rinetd:0.52</vuln:product>
      <vuln:product>cpe:/a:rinetd:rinetd:0.61</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0212</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:15.930-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-289" xml:lang="en">DSA-289</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105059298502830&amp;w=2" xml:lang="en">20030417 Vulnerability in rinetd</vuln:reference>
    </vuln:references>
    <vuln:summary>handleAccept in rinetd before 0.62 does not properly resize the connection list when it becomes full and sets an array index incorrectly, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large number of connections.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0213">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:poptop:pptp_server:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:poptop:pptp_server:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:poptop:pptp_server:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:poptop:pptp_server:1.1.3_2002-10-09"/>
        <cpe-lang:fact-ref name="cpe:/a:poptop:pptp_server:1.1.4b1"/>
        <cpe-lang:fact-ref name="cpe:/a:poptop:pptp_server:1.1.4b2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:poptop:pptp_server:1.1.3</vuln:product>
      <vuln:product>cpe:/a:poptop:pptp_server:1.1.4b2</vuln:product>
      <vuln:product>cpe:/a:poptop:pptp_server:1.1.4b1</vuln:product>
      <vuln:product>cpe:/a:poptop:pptp_server:1.1.2</vuln:product>
      <vuln:product>cpe:/a:poptop:pptp_server:1.0.1</vuln:product>
      <vuln:product>cpe:/a:poptop:pptp_server:1.1.3_2002-10-09</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0213</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:46.287-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/673993" xml:lang="en">VU#673993</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7316" xml:lang="en">7316</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/317995" xml:lang="en">20030409 PoPToP PPTP server remotely exploitable buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-295" xml:lang="en">DSA-295</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2003_029.html" xml:lang="en">SuSE-SA:2003:029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105068728421160&amp;w=2" xml:lang="en">20030418 Exploit for PoPToP PPTP server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/319428" xml:lang="en">20030422 Re: Exploit for PoPToP PPTP server - Linux version</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=138437" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=138437</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154539727967&amp;w=2" xml:lang="en">20030428 GLSA:  pptpd (200304-08)</vuln:reference>
    </vuln:references>
    <vuln:summary>ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length field of 0 or 1, which causes a negative value to be fed into a read operation, leading to a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0214">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.16"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.17"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.18"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.19"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.20"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.21"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:mime-support:3.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:debian:mime-support:3.15</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.13</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.12</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.9</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.19</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.18</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.16</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.14</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.10</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.17</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.11</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.20</vuln:product>
      <vuln:product>cpe:/a:debian:mime-support:3.21</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0214</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:46.443-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2003/dsa-292" xml:lang="en">DSA-292</vuln:reference>
    </vuln:references>
    <vuln:summary>run-mailcap in mime-support 3.22 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0215">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:battleaxe_software:bttlxeforum:2.0_beta_3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:battleaxe_software:bttlxeforum:2.0_beta_3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0215</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:16.603-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.battleaxesoftware.com/forums/forum.asp?forumid=36&amp;select=1812" xml:lang="en">http://www.battleaxesoftware.com/forums/forum.asp?forumid=36&amp;select=1812</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105120052725940&amp;w=2" xml:lang="en">20030424 SQL injection in BttlxeForum</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1006632" xml:lang="en">1006632</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in bttlxeForum 2.0 beta 3 and earlier allows remote attackers to bypass authentication via the (1) username and (2) password fields, and possibly other fields.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0216">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cisco:catos:7.5%281%29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:catos:7.5%281%29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0216</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:16.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/443257" xml:lang="en">VU#443257</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20030424-catos.shtml." xml:lang="en">20030424 Cisco Security Advisory: Cisco Catalyst Enable Password Bypass Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0217">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:neoteris:instant_virtual_extranet:3.01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:neoteris:instant_virtual_extranet:3.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0217</vuln:cve-id>
    <vuln:published-datetime>2003-06-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:18:16.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105283833617480&amp;w=2" xml:lang="en">20030513 XSS In Neoteris IVE Allows Session Hijacking</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Neoteris Instant Virtual Extranet (IVE) 3.01 and earlier allows remote attackers to insert arbitrary web script and bypass authentication via a certain CGI script.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0218">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:monkey-project:monkey_http_daemon:0.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:monkey-project:monkey_http_daemon:0.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:monkey-project:monkey_http_daemon:0.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:monkey-project:monkey_http_daemon:0.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:monkey-project:monkey_http_daemon:0.6.0</vuln:product>
      <vuln:product>cpe:/a:monkey-project:monkey_http_daemon:0.1.1</vuln:product>
      <vuln:product>cpe:/a:monkey-project:monkey_http_daemon:0.5.2</vuln:product>
      <vuln:product>cpe:/a:monkey-project:monkey_http_daemon:0.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0218</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-24T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7202" xml:lang="en">7202</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154473526898&amp;w=2" xml:lang="en">20030428 GLSA:  monkeyd (200304-07.1)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0029.html" xml:lang="en">20030420 Monkey HTTPd Remote Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://monkeyd.sourceforge.net/Changelog.txt" xml:lang="en">http://monkeyd.sourceforge.net/Changelog.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105094204204166&amp;w=2" xml:lang="en">20030420 Monkey HTTPd Remote Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in PostMethod() function for Monkey HTTP Daemon (monkeyd) 0.6.1 and earlier allows remote attackers to execute arbitrary code via a POST request with a large body.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0219">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall_2:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall_2:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall_2:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall_2:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall_2:2.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kerio:personal_firewall_2:2.1.4</vuln:product>
      <vuln:product>cpe:/a:kerio:personal_firewall_2:2.1.1</vuln:product>
      <vuln:product>cpe:/a:kerio:personal_firewall_2:2.1</vuln:product>
      <vuln:product>cpe:/a:kerio:personal_firewall_2:2.1.2</vuln:product>
      <vuln:product>cpe:/a:kerio:personal_firewall_2:2.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0219</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:47.193-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/641012" xml:lang="en">VU#641012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7179" xml:lang="en">7179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105155734411836&amp;w=2" xml:lang="en">20030428 CORE-2003-0305-02: Vulnerabilities in Kerio Personal Firewall</vuln:reference>
    </vuln:references>
    <vuln:summary>Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid session and replaying them against the remote administration server.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0220">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall_2:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall_2:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall_2:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall_2:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:kerio:personal_firewall_2:2.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kerio:personal_firewall_2:2.1.4</vuln:product>
      <vuln:product>cpe:/a:kerio:personal_firewall_2:2.1.1</vuln:product>
      <vuln:product>cpe:/a:kerio:personal_firewall_2:2.1</vuln:product>
      <vuln:product>cpe:/a:kerio:personal_firewall_2:2.1.2</vuln:product>
      <vuln:product>cpe:/a:kerio:personal_firewall_2:2.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0220</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:47.347-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/454716" xml:lang="en">VU#454716</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10" xml:lang="en">http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7180" xml:lang="en">7180</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105155734411836&amp;w=2" xml:lang="en">20030428 CORE-2003-0305-02: Vulnerabilities in Kerio Personal Firewall</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute arbitrary code via a handshake packet.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0221">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:5.1b:pk1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:tru64:5.1b:pk1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0221</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:33:47.503-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/11892" xml:lang="en">tru64-dupatch-setld-symlink(11892)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7452" xml:lang="en">7452</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/n-086.shtml" xml:lang="en">SSRT3471</vuln:reference>
    </vuln:references>
    <vuln:summary>The (1) dupatch and (2) setld utilities in HP Tru64 UNIX 5.1B PK1 and earlier allows local users to overwrite files and possibly gain root privileges via a symlink attack.</vuln:summary>
  </entry>
  <entry id="CVE-2003-0222">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:7.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:7.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.0.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.0.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.0x"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle8i:8.1x"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:oracle9i:9.2.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:oracle8i:8.1.7</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.1.5</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.1.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.1.7.4</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.2.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.0.6.3</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.2.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.1.5</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.1.6</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.2.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.1.3</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.0.3</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.1.7.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.0.1.4</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:7.3.3</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.0.5.1</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.1x</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:7.3.4</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.1.6</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.0.6</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle8i:8.0x</vuln:product>
      <vuln:product>cpe:/a:oracle:oracle9i:9.2.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.0.4</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.0.5</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.1.7</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:8.0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2003-0222</vuln:cve-id>
    <vuln:published-datetime>2003-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
   