<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" nvd_xml_version="2.0" pub_date="2009-11-23T03:50:00" xsi:schemaLocation="http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
    <entry id="CVE-2004-1776">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%283%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%283%29t" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:cisco:ios:12.1%283%29</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.1%283%29t</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-1776</vuln:cve-id>
        <vuln:published-datetime>2001-02-28T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:42:19.710-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-30T20:49:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/840665">VU#840665</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/6180">cisco-ios-cable-docsis(6180)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CISCO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cisco.com/warp/public/707/ios-snmp-community-vulns-pub.shtml">20041008 Cisco IOS Software Multiple SNMP Community String Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:summary>Cisco IOS 12.1(3) and 12.1(3)T allows remote attackers to read and modify device configuration data via the cable-docsis read-write community string used by the Data Over Cable Service Interface Specification (DOCSIS) standard.</vuln:summary>
    </entry>
    <entry id="CVE-2004-1784">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:webcam_corp:webcam_watchdog:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:webcam_corp:webcam_watchdog:1.1" />
                <cpe-lang:fact-ref name="cpe:/a:webcam_corp:webcam_watchdog:3.63" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:webcam_corp:webcam_watchdog:1.0</vuln:product>
            <vuln:product>cpe:/a:webcam_corp:webcam_watchdog:1.1</vuln:product>
            <vuln:product>cpe:/a:webcam_corp:webcam_watchdog:3.63</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-1784</vuln:cve-id>
        <vuln:published-datetime>2004-01-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:42:20.897-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-30T20:31:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10527">10527</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14131">webcam-watchdog-get-bo(14131)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.webcamsoft.com/en/watchdog_h.html">http://www.webcamsoft.com/en/watchdog_h.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9351">9351</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/348818">20040103 Webcam Watchdog Stack Overflow Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3312">3312</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.elitehaven.net/webcamwatchdog.txt">http://www.elitehaven.net/webcamwatchdog.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the web server of Webcam Watchdog 3.63 allows remote attackers to execute arbitrary code via a long HTTP GET request.</vuln:summary>
    </entry>
    <entry id="CVE-2004-1785">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:invision_power_services:invision_board:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:invision_power_services:invision_board:1.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:invision_power_services:invision_board:1.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:invision_power_services:invision_board:1.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:invision_power_services:invision_board:1.2" />
                <cpe-lang:fact-ref name="cpe:/a:invision_power_services:invision_board:1.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:invision_power_services:invision_board:1.3</vuln:product>
            <vuln:product>cpe:/a:invision_power_services:invision_board:1.2</vuln:product>
            <vuln:product>cpe:/a:invision_power_services:invision_board:1.0.1</vuln:product>
            <vuln:product>cpe:/a:invision_power_services:invision_board:1.0</vuln:product>
            <vuln:product>cpe:/a:invision_power_services:invision_board:1.1.1</vuln:product>
            <vuln:product>cpe:/a:invision_power_services:invision_board:1.1.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-1785</vuln:cve-id>
        <vuln:published-datetime>2004-01-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:42:21.053-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-30T19:43:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9353">9353</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3319">3319</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10530">10530</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/348821">20040103 [SCSA-025] Invision Power Board SQL Injection Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008589">1008589</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable.</vuln:summary>
    </entry>
    <entry id="CVE-2004-1786">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:iatek:portalapp" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:iatek:portalapp</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-1786</vuln:cve-id>
        <vuln:published-datetime>2004-01-04T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:42:21.210-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-30T19:38:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14169">portalapp-url-access-database(14169)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9354">9354</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1008627">1008627</vuln:reference>
        </vuln:references>
        <vuln:summary>PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb.</vuln:summary>
    </entry>
    <entry id="CVE-2004-1000">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:debian:lintian:1.2_0.17.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:debian:lintian:1.2_0.17.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-1000</vuln:cve-id>
        <vuln:published-datetime>2004-01-10T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:40:02.827-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-17T14:29:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18808">lintian-symlink(18808)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13771">13771</vuln:reference>
        </vuln:references>
        <vuln:summary>lintian 1.23 and earlier removes the working directory even if it was not created by lintian, which may allow local users to delete arbitrary files or directories via a symlink attack.</vuln:summary>
    </entry>
    <entry id="CVE-2004-1124">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.6" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.7" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.1.3" />
                <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.1.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sco:openserver:5.0.7</vuln:product>
            <vuln:product>cpe:/o:sco:unixware:7.1.1</vuln:product>
            <vuln:product>cpe:/o:sco:unixware:7.1.3</vuln:product>
            <vuln:product>cpe:/o:sco:unixware:7.1.4</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-1124</vuln:cve-id>
        <vuln:published-datetime>2004-01-14T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:40:27.263-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-17T18:52:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18970">chroot-jail-security-bypass(18970)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SCO</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.2/SCOSA-2005.2.txt">SCOSA-2005.2</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12300">12300</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15339">15339</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13915">13915</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SCO</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.22/SCOSA-2005.22.txt">SCOSA-2005.22</vuln:reference>
        </vuln:references>
        <vuln:summary>Unknown vulnerability in chroot on SCO UnixWare 7.1.1 through 7.1.4 allows local users to escape the chroot jail and conduct unauthorized activities.</vuln:summary>
    </entry>
    <entry id="CVE-2004-1764">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.22" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:11.4</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:11.22</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-1764</vuln:cve-id>
        <vuln:published-datetime>2004-01-14T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-03-04T00:26:14.877-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-30T21:36:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:5789" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5789" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/406406">VU#406406</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14828">hp-libdtsvc-bo(14828)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/advisories/6237">HPSBUX0401-308</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/o-057.shtml">O-057</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in CDE libDtSvc on HP-UX B.11.00, B.11.04, B.11.11, and B.11.22 allows local users to gain root privileges via unknown vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0011">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:debian:fsp:2.81.b18" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:debian:fsp:2.81.b18</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0011</vuln:cve-id>
        <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:18.040-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9377">9377</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-416">DSA-416</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14155">fsp-boundry-error-bo(14155)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/o-048.shtml">O-048</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in fsp before 2.81.b18 allows remote users to execute arbitrary code.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0014">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:nd:nd:0.8.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:nd:nd:0.8.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0014</vuln:cve-id>
        <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:24:50.710-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9365">9365</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-412">DSA-412</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14141">nd-long-string-bo(14141)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008616">1008616</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10550">10550</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10549">10549</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple buffer overflows in the nd WebDAV interface 0.8.2 and earlier allows remote web servers to execute arbitrary code via certain long strings.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0037">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:opentext:opentext_firstclass_desktop_client:7.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:opentext:opentext_firstclass_desktop_client:7.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0037</vuln:cve-id>
        <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:20.303-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14151">firstclassclient-execute-code(14151)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9370">9370</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3442">3442</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10556">10556</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340950611167&amp;w=2">20040105 FirstClass Client 7.1: Command Execution via Email Web Link</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008609">1008609</vuln:reference>
        </vuln:references>
        <vuln:summary>FirstClass Desktop Client 7.1 allows remote attackers to execute arbitrary commands via hyperlinks in FirstClass RTF messages.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0036">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:2.3.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:jelsoft:vbulletin:2.3.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0036</vuln:cve-id>
        <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:20.163-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340358202123&amp;w=2">20040105 vBulletin Forum 2.3.xx calendar.php SQL Injection</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14144">vbulletin-calendar-sql-injection(14144)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vbulletin.com/forum/showthread.php?postid=588825">http://www.vbulletin.com/forum/showthread.php?postid=588825</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9360">9360</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3344">3344</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in calendar.php for vBulletin Forum 2.3.x before 2.3.4 allows remote attackers to steal sensitive information via the eventid parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0035">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:3.4.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phorum:phorum:3.4.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0035</vuln:cve-id>
        <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:20.023-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14146">phorum-register-sql-injection(14146)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9363">9363</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340481804110&amp;w=2">20040105 Multiple Vulnerabilities in Phorum 3.4.5</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3508">3508</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10567">10567</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in register.php for Phorum 3.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the hide_email parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0034">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:3.4.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phorum:phorum:3.4.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0034</vuln:cve-id>
        <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:19.867-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14145">phorum-common-xss(14145)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9361">9361</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10567">10567</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://phorum.org/">http://phorum.org/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340481804110&amp;w=2">20040105 Multiple Vulnerabilities in Phorum 3.4.5</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008633">1008633</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3510">3510</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3506">3506</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3434">3434</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.4.5 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the phorum_check_xss function in common.php, (2) the EditError variable in profile.php, and (3) the Error variable in login.php.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0033">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.61" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpgedview:phpgedview:2.61</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0033</vuln:cve-id>
        <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:19.727-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14162">phpgedview-admin-info-disclosure(14162)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9371">9371</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3404">3404</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10565">10565</vuln:reference>
        </vuln:references>
        <vuln:summary>admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0032">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.61" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpgedview:phpgedview:2.61</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0032</vuln:cve-id>
        <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:19.570-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14160">phpgedview-search-xss(14160)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9369">9369</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3402">3402</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10565">10565</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script via the firstname parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0031">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.61" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpgedview:phpgedview:2.61</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0031</vuln:cve-id>
        <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:19.430-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14161">phpgedview-modify-admin-password(14161)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3403">3403</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10565">10565</vuln:reference>
        </vuln:references>
        <vuln:summary>PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTTP request to editconfig.php.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0030">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.61" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpgedview:phpgedview:2.61</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0030</vuln:cve-id>
        <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:19.273-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14159">phpgedview-pgvbasedirectory-file-include(14159)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9368">9368</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3343">3343</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10565">10565</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008632">1008632</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0029">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.0.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ibm:lotus_domino:6.0.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0029</vuln:cve-id>
        <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:19.133-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14153">lotus-notes-insecure-permissions(14153)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9366">9366</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008623">1008623</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3424">3424</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.excluded.org/advisories/advisory05.txt">http://www.excluded.org/advisories/advisory05.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10566">10566</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340897710308&amp;w=2">20040106 Lotus Notes Domino 6.0.2 (linux) faulty default permissions</vuln:reference>
        </vuln:references>
        <vuln:summary>Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-2004-1766">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:juniper:netscreen-security_manager_2004" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:cve-id>CVE-2004-1766</vuln:cve-id>
        <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:42:17.943-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-30T21:32:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/CRDY-5VEU8N">http://www.kb.cert.org/vuls/id/CRDY-5VEU8N</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/927630">VU#927630</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14886">netscreen-information-disclosure(14886)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9455">9455</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10675">10675</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3613">3613</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.juniper.net/support/security/alerts/58290.txt">http://www.juniper.net/support/security/alerts/58290.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>The default installation of NetScreen-Security Manager before Feature Pack 1 does not enable encryption for communication with devices running ScreenOS 5.0, which allows remote attackers to obtain sensitive information via sniffing.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2127">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:leif_m._wright:web_blog:1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:leif_m._wright:web_blog:1.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2127</vuln:cve-id>
        <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:16.267-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-27T16:14:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14978">webblog-dotdot-directory-traversal(14978)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.zone-h.org/en/advisories/read/id=3822/">http://www.zone-h.org/en/advisories/read/id=3822/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9517">9517</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107531194527602&amp;w=2">20040128 ZH2004-01SA (security advisory): Web Blog 1.1 Remote arbitrary</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3739">3739</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10740">10740</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in Web Blog 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file variable.</vuln:summary>
    </entry>
    <entry id="CVE-2004-1759">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:cisco:emergency_responder:1.1" />
                <cpe-lang:fact-ref name="cpe:/a:cisco:ip_call_center_express_enhanced:3.0" />
                <cpe-lang:fact-ref name="cpe:/a:cisco:ip_call_center_express_standard:3.0" />
                <cpe-lang:fact-ref name="cpe:/a:cisco:ip_interactive_voice_response:3.0" />
                <cpe-lang:fact-ref name="cpe:/a:cisco:personal_assistant:1.3%281%29" />
                <cpe-lang:fact-ref name="cpe:/a:cisco:personal_assistant:1.3%282%29" />
                <cpe-lang:fact-ref name="cpe:/a:cisco:personal_assistant:1.3%283%29" />
                <cpe-lang:fact-ref name="cpe:/a:cisco:personal_assistant:1.3%284%29" />
                <cpe-lang:fact-ref name="cpe:/a:cisco:personal_assistant:1.4%281%29" />
                <cpe-lang:fact-ref name="cpe:/a:cisco:personal_assistant:1.4%282%29" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:director_agent:2.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:director_agent:3.11" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager:1.0" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager:2.0" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager:3.0" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager:3.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager:3.1%282%29" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager:3.1%283a%29" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager:3.2" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager:3.3" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager:3.3%283%29" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager:4.0" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:internet_service_node" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:cisco:conference_connection:1.1%281%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:conference_connection:1.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:ibm:mcs-7815-1000" />
                <cpe-lang:fact-ref name="cpe:/h:ibm:mcs-7815i-2.0" />
                <cpe-lang:fact-ref name="cpe:/h:ibm:mcs-7835i-2.4" />
                <cpe-lang:fact-ref name="cpe:/h:ibm:mcs-7835i-3.0" />
                <cpe-lang:fact-ref name="cpe:/h:ibm:x330:8654" />
                <cpe-lang:fact-ref name="cpe:/h:ibm:x330:8674" />
                <cpe-lang:fact-ref name="cpe:/h:ibm:x340" />
                <cpe-lang:fact-ref name="cpe:/h:ibm:x342" />
                <cpe-lang:fact-ref name="cpe:/h:ibm:x345" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:ibm:mcs-7815i-2.0</vuln:product>
            <vuln:product>cpe:/h:cisco:call_manager:1.0</vuln:product>
            <vuln:product>cpe:/a:cisco:personal_assistant:1.3%282%29</vuln:product>
            <vuln:product>cpe:/h:cisco:call_manager:3.1%282%29</vuln:product>
            <vuln:product>cpe:/a:cisco:personal_assistant:1.3%284%29</vuln:product>
            <vuln:product>cpe:/a:cisco:personal_assistant:1.4%282%29</vuln:product>
            <vuln:product>cpe:/h:cisco:call_manager:3.1%283a%29</vuln:product>
            <vuln:product>cpe:/h:ibm:x345</vuln:product>
            <vuln:product>cpe:/h:ibm:mcs-7815-1000</vuln:product>
            <vuln:product>cpe:/h:ibm:x340</vuln:product>
            <vuln:product>cpe:/h:ibm:x330:8674</vuln:product>
            <vuln:product>cpe:/h:ibm:x342</vuln:product>
            <vuln:product>cpe:/h:ibm:x330:8654</vuln:product>
            <vuln:product>cpe:/a:cisco:ip_call_center_express_standard:3.0</vuln:product>
            <vuln:product>cpe:/h:cisco:call_manager:2.0</vuln:product>
            <vuln:product>cpe:/o:cisco:conference_connection:1.1%281%29</vuln:product>
            <vuln:product>cpe:/a:cisco:ip_call_center_express_enhanced:3.0</vuln:product>
            <vuln:product>cpe:/h:cisco:call_manager:3.0</vuln:product>
            <vuln:product>cpe:/h:cisco:call_manager:3.3</vuln:product>
            <vuln:product>cpe:/h:cisco:call_manager:3.1</vuln:product>
            <vuln:product>cpe:/h:cisco:call_manager:3.2</vuln:product>
            <vuln:product>cpe:/a:cisco:personal_assistant:1.3%283%29</vuln:product>
            <vuln:product>cpe:/a:cisco:personal_assistant:1.4%281%29</vuln:product>
            <vuln:product>cpe:/a:cisco:personal_assistant:1.3%281%29</vuln:product>
            <vuln:product>cpe:/a:cisco:emergency_responder:1.1</vuln:product>
            <vuln:product>cpe:/a:cisco:ip_interactive_voice_response:3.0</vuln:product>
            <vuln:product>cpe:/o:cisco:conference_connection:1.2</vuln:product>
            <vuln:product>cpe:/a:ibm:director_agent:2.2</vuln:product>
            <vuln:product>cpe:/h:cisco:call_manager:3.3%283%29</vuln:product>
            <vuln:product>cpe:/a:ibm:director_agent:3.11</vuln:product>
            <vuln:product>cpe:/h:ibm:mcs-7835i-3.0</vuln:product>
            <vuln:product>cpe:/h:ibm:mcs-7835i-2.4</vuln:product>
            <vuln:product>cpe:/h:cisco:call_manager:4.0</vuln:product>
            <vuln:product>cpe:/h:cisco:internet_service_node</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-1759</vuln:cve-id>
        <vuln:published-datetime>2004-01-21T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:42:16.630-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-31T08:43:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-399" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/721092">VU#721092</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9469">9469</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CISCO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cisco.com/warp/public/707/cisco-sa-20040121-voice.shtml">20040121 Voice Product Vulnerabilities on IBM Servers</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10696">10696</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14901">ciscovoice-ibmservers-dos(14901)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008814">1008814</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3691">3691</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/o-066.shtml">O-066</vuln:reference>
        </vuln:references>
        <vuln:summary>Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning.</vuln:summary>
    </entry>
    <entry id="CVE-2004-1760">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:cisco:emergency_responder:1.1" />
                <cpe-lang:fact-ref name="cpe:/a:cisco:ip_call_center_express_enhanced:3.0" />
                <cpe-lang:fact-ref name="cpe:/a:cisco:ip_call_center_express_standard:3.0" />
                <cpe-lang:fact-ref name="cpe:/a:cisco:ip_interactive_voice_response:3.0" />
                <cpe-lang:fact-ref name="cpe:/a:cisco:personal_assistant:1.3%281%29" />
                <cpe-lang:fact-ref name="cpe:/a:cisco:personal_assistant:1.3%282%29" />
                <cpe-lang:fact-ref name="cpe:/a:cisco:personal_assistant:1.3%283%29" />
                <cpe-lang:fact-ref name="cpe:/a:cisco:personal_assistant:1.3%284%29" />
                <cpe-lang:fact-ref name="cpe:/a:cisco:personal_assistant:1.4%281%29" />
                <cpe-lang:fact-ref name="cpe:/a:cisco:personal_assistant:1.4%282%29" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:director_agent:2.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:director_agent:3.11" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager:1.0" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager:2.0" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager:3.0" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager:3.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager:3.1%282%29" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager:3.1%283a%29" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager:3.2" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager:3.3" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager:3.3%283%29" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager:4.0" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:internet_service_node" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:cisco:conference_connection:1.1%281%29" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:conference_connection:1.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:ibm:mcs-7815-1000" />
                <cpe-lang:fact-ref name="cpe:/h:ibm:mcs-7815i-2.0" />
                <cpe-lang:fact-ref name="cpe:/h:ibm:mcs-7835i-2.4" />
                <cpe-lang:fact-ref name="cpe:/h:ibm:mcs-7835i-3.0" />
                <cpe-lang:fact-ref name="cpe:/h:ibm:x330:8654" />
                <cpe-lang:fact-ref name="cpe:/h:ibm:x330:8674" />
                <cpe-lang:fact-ref name="cpe:/h:ibm:x340" />
                <cpe-lang:fact-ref name="cpe:/h:ibm:x342" />
                <cpe-lang:fact-ref name="cpe:/h:ibm:x345" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:ibm:mcs-7815i-2.0</vuln:product>
            <vuln:product>cpe:/h:cisco:call_manager:1.0</vuln:product>
            <vuln:product>cpe:/a:cisco:personal_assistant:1.3%282%29</vuln:product>
            <vuln:product>cpe:/h:cisco:call_manager:3.1%282%29</vuln:product>
            <vuln:product>cpe:/a:cisco:personal_assistant:1.3%284%29</vuln:product>
            <vuln:product>cpe:/a:cisco:personal_assistant:1.4%282%29</vuln:product>
            <vuln:product>cpe:/h:cisco:call_manager:3.1%283a%29</vuln:product>
            <vuln:product>cpe:/h:ibm:x345</vuln:product>
            <vuln:product>cpe:/h:ibm:mcs-7815-1000</vuln:product>
            <vuln:product>cpe:/h:ibm:x340</vuln:product>
            <vuln:product>cpe:/h:ibm:x330:8674</vuln:product>
            <vuln:product>cpe:/h:ibm:x342</vuln:product>
            <vuln:product>cpe:/h:ibm:x330:8654</vuln:product>
            <vuln:product>cpe:/a:cisco:ip_call_center_express_standard:3.0</vuln:product>
            <vuln:product>cpe:/h:cisco:call_manager:2.0</vuln:product>
            <vuln:product>cpe:/o:cisco:conference_connection:1.1%281%29</vuln:product>
            <vuln:product>cpe:/a:cisco:ip_call_center_express_enhanced:3.0</vuln:product>
            <vuln:product>cpe:/h:cisco:call_manager:3.0</vuln:product>
            <vuln:product>cpe:/h:cisco:call_manager:3.3</vuln:product>
            <vuln:product>cpe:/h:cisco:call_manager:3.1</vuln:product>
            <vuln:product>cpe:/h:cisco:call_manager:3.2</vuln:product>
            <vuln:product>cpe:/a:cisco:personal_assistant:1.3%283%29</vuln:product>
            <vuln:product>cpe:/a:cisco:personal_assistant:1.4%281%29</vuln:product>
            <vuln:product>cpe:/a:cisco:personal_assistant:1.3%281%29</vuln:product>
            <vuln:product>cpe:/a:cisco:emergency_responder:1.1</vuln:product>
            <vuln:product>cpe:/a:cisco:ip_interactive_voice_response:3.0</vuln:product>
            <vuln:product>cpe:/o:cisco:conference_connection:1.2</vuln:product>
            <vuln:product>cpe:/a:ibm:director_agent:2.2</vuln:product>
            <vuln:product>cpe:/h:cisco:call_manager:3.3%283%29</vuln:product>
            <vuln:product>cpe:/a:ibm:director_agent:3.11</vuln:product>
            <vuln:product>cpe:/h:ibm:mcs-7835i-3.0</vuln:product>
            <vuln:product>cpe:/h:ibm:mcs-7835i-2.4</vuln:product>
            <vuln:product>cpe:/h:cisco:call_manager:4.0</vuln:product>
            <vuln:product>cpe:/h:cisco:internet_service_node</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-1760</vuln:cve-id>
        <vuln:published-datetime>2004-01-21T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:42:16.867-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-31T08:40:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/602734">VU#602734</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14900">ciscovoice-ibmservers-admin-access(14900)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9468">9468</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CISCO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cisco.com/warp/public/707/cisco-sa-20040121-voice.shtml">20040121 Voice Product Vulnerabilities on IBM Servers</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10696">10696</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008814">1008814</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3692">3692</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/o-066.shtml">O-066</vuln:reference>
        </vuln:references>
        <vuln:summary>The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2120">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:reptile_web_server:reptile_web_server:2002-01-05" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:reptile_web_server:reptile_web_server:2002-01-05</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2120</vuln:cve-id>
        <vuln:published-datetime>2004-01-23T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:15.143-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-27T16:33:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14932">reptilewebserver-get-dos(14932)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9482">9482</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.autistici.org/fdonato/advisory/reptilewsDailyVersion-adv.txt">http://www.autistici.org/fdonato/advisory/reptilewsDailyVersion-adv.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1008842">1008842</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107497355713434&amp;w=2">20040124 Resources consumption in Reptile webserver daily version</vuln:reference>
        </vuln:references>
        <vuln:summary>Reptile Web Server allows remote attackers to cause a denial of service (CPU consumption) via multiple incomplete GET requests without the HTTP version.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2117">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:tinyserver:tinyserver:1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:tinyserver:tinyserver:1.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2117</vuln:cve-id>
        <vuln:published-datetime>2004-01-24T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:32:59.197-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-27T16:46:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14928">tinyserver-string-dos(14928)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9485">9485</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.autistici.org/fdonato/advisory/tinyServer1.1%5B1.0.5%5D-adv.txt">http://www.autistici.org/fdonato/advisory/tinyServer1.1[1.0.5]-adv.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107496530806730&amp;w=2">20040124 Tiny Server 1.1 (1.0.5) Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3709">3709</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10707">10707</vuln:reference>
        </vuln:references>
        <vuln:summary>Tiny Server 1.1 allows remote attackers to cause a denial of service (crash) via malformed HTTP requests such as (1) a GET request without the HTTP version (HTTP/1.1), or (2) a request without GET or the HTTP version.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2122">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:intra_forum:intra_forum" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:intra_forum:intra_forum</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2122</vuln:cve-id>
        <vuln:published-datetime>2004-01-24T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T00:35:46.267-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-27T16:25:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14933">intraforum-intraforumcgi-xss(14933)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008839">1008839</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107497803617071&amp;w=2">20040124 Inrtra Forum Cross Site Scripting Vulnerabillity</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra Forum allows remote attackers to inject arbitrary web script or HTML via the (1) use_last_read or (2) forum parameters.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2131">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ibm:informix_dynamic_server:9.40.uc1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:informix_dynamic_server:9.40.uc2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:informix_extended_parallel_server:8.40_uc1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ibm:informix_dynamic_server:9.40.uc2</vuln:product>
            <vuln:product>cpe:/a:ibm:informix_dynamic_server:9.40.uc1</vuln:product>
            <vuln:product>cpe:/a:ibm:informix_extended_parallel_server:8.40_uc1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2131</vuln:cve-id>
        <vuln:published-datetime>2004-01-27T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:16.910-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-27T15:58:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9512">9512</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg21153336">http://www-1.ibm.com/support/docview.wss?uid=swg21153336</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107539878804074&amp;w=2">20040129 ----------========== OPEN3S-2003-08-08-eng-informix-ontape</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14970">informix-ontape-binary-bo(14970)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3759">3759</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10737/">10737</vuln:reference>
        </vuln:references>
        <vuln:summary>Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCONFIG environment variable.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2134">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:9.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:9.0.2.0.0" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:9.0.2.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:9.0.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:9.0.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:9.0.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:9.0.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:oracle:application_server:9.0.2.3</vuln:product>
            <vuln:product>cpe:/a:oracle:application_server:9.0.2</vuln:product>
            <vuln:product>cpe:/a:oracle:application_server:9.0.3</vuln:product>
            <vuln:product>cpe:/a:oracle:application_server:9.0.2.2</vuln:product>
            <vuln:product>cpe:/a:oracle:application_server:9.0.2.1</vuln:product>
            <vuln:product>cpe:/a:oracle:application_server:9.0.2.0.0</vuln:product>
            <vuln:product>cpe:/a:oracle:application_server:9.0.2.0.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2134</vuln:cve-id>
        <vuln:published-datetime>2004-01-28T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:17.377-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-27T15:40:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9515">9515</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULN-DEV</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/82/351719">20040128 Re: Oracle toplink mapping workbench password algorithm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.planet-source-code.com/vb/scripts/ShowCode.asp?txtCodeId=803&amp;lngWId=5">http://www.planet-source-code.com/vb/scripts/ShowCode.asp?txtCodeId=803&amp;lngWId=5</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107531028325112&amp;w=2">20040128 Oracle toplink mapping workbench password algorithm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/352315/30/21430/threaded">20040128 Re: Oracle toplink mapping workbench password algorithm</vuln:reference>
        </vuln:references>
        <vuln:summary>Oracle toplink mapping workBench uses a weak encryption algorithm for passwords, which allows local users to decrypt the passwords.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2034">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:wildtangent:webdriver:4.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:wildtangent:webdriver:4.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2034</vuln:cve-id>
        <vuln:published-datetime>2004-01-29T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:01.473-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-25T16:57:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/16266">wildtangent-wthoster-webdriver-bo(16266)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/10421">10421</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/6445">6445</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ngssoftware.com/advisories/wildtangent.txt">http://www.ngssoftware.com/advisories/wildtangent.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/11727">11727</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108569235217149&amp;w=2">20040527 WildTangent Web Driver Long FileName Stack Overflow</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the (1) WTHoster and (2) WebDriver modules in WildTangent Web Driver 4.0 allows remote attackers to execute arbitrary code via a long filename.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2132">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:pj_cgi_neo_review:pj_cgi_neo_review" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:pj_cgi_neo_review:pj_cgi_neo_review</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2132</vuln:cve-id>
        <vuln:published-datetime>2004-01-29T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:17.067-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-27T15:52:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14980">pjcgineoreview-dotdot-directory-traversal(14980)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.zone-h.org/advisories/read/id=3824">http://www.zone-h.org/advisories/read/id=3824</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9524">9524</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107539804702913&amp;w=2">20040129 ZH2004-02SA (security advisory): PJ CGI Neo review (NeoBoard review) Remote arbitrary file retrieving</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.secunia.com/advisories/10734/">10734</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3746">3746</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in PJreview_Neo.cgi in PJ CGI Neo review allows remote attackers to read arbitrary files via a ..  (dot dot) in the p parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2133">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:cvsup:cvsup:cvsup-16.1h-2.i386.rpm" />
                <cpe-lang:fact-ref name="cpe:/a:cvsup:cvsup:cvsup-16.1h-36.i586.rpm" />
                <cpe-lang:fact-ref name="cpe:/a:cvsup:cvsup:cvsup-16.1h-43.i586.rpm" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:cvsup:cvsup:cvsup-16.1h-43.i586.rpm</vuln:product>
            <vuln:product>cpe:/a:cvsup:cvsup:cvsup-16.1h-36.i586.rpm</vuln:product>
            <vuln:product>cpe:/a:cvsup:cvsup:cvsup-16.1h-2.i386.rpm</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2133</vuln:cve-id>
        <vuln:published-datetime>2004-01-29T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:17.220-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-27T15:47:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14994">cvsup-rpath-gain-privileges(14994)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9523">9523</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107539776002450&amp;w=2">20040129 Security Announcement: untrusted ELF library path in some cvsup binary RPMs</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0025.html">20040129 Security Announcement: untrusted ELF library path in some cvsup binary RPMs</vuln:reference>
        </vuln:references>
        <vuln:summary>Certain third-party packages for CVSup 16.1h, such as SuSE Linux, contain untrusted paths in the ELF RPATH fields of certain executables, which could allow local users to execute arbitrary code by causing cvsup to link against malicious libraries that are created in world-writable directories such as /usr/src/packages.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0028">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:samba:jitterbug:1.6.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:samba:jitterbug:1.6.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0028</vuln:cve-id>
        <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:18.977-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-420">DSA-420</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9397">9397</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14207">jitterbug-execute-code(14207)</vuln:reference>
        </vuln:references>
        <vuln:summary>jitterbug 1.6.2 does not properly sanitize inputs, which allows remote authenticated users to execute arbitrary commands.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0017">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpgroupware:phpgroupware:0.9.14" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpgroupware:phpgroupware:0.9.14</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0017</vuln:cve-id>
        <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:18.773-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-419">DSA-419</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9386">9386</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008662">1008662</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10591">10591</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform unauthorized database operations.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0016">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpgroupware:phpgroupware:0.9.14" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpgroupware:phpgroupware:0.9.14</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0016</vuln:cve-id>
        <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:18.633-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-419">DSA-419</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9387">9387</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/13489">phpgroupware-calendar-file-include(13489)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/6860">6860</vuln:reference>
        </vuln:references>
        <vuln:summary>The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers to create and execute PHP files.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0015">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:vbox3:vbox3:0.1.8" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:vbox3:vbox3:0.1.8</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0015</vuln:cve-id>
        <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:18.477-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-418">DSA-418</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9381">9381</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14170">vbox3-gain-privileges(14170)</vuln:reference>
        </vuln:references>
        <vuln:summary>vbox3 0.1.8 and earlier does not properly drop privileges before executing a user-provided TCL script, which allows local users to gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0013">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:jabber_software_foundation:jabber_server:1.4.2a" />
                <cpe-lang:fact-ref name="cpe:/a:jabber_software_foundation:jabber_server:1.4.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:jabber_software_foundation:jabber_server:1.4.2a</vuln:product>
            <vuln:product>cpe:/a:jabber_software_foundation:jabber_server:1.4.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0013</vuln:cve-id>
        <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:18.180-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:005">MDKSA-2004:005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-414">DSA-414</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14158">jabber-ssl-connections-dos(14158)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9376">9376</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3345">3345</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10559">10559</vuln:reference>
        </vuln:references>
        <vuln:summary>jabber 1.4.2, 1.4.2a, and possibly earlier versions, does not properly handle SSL connections, which allows remote attackers to cause a denial of service (crash).</vuln:summary>
    </entry>
    <entry id="CVE-2004-0046">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:snapstream:snapstream_pvs:lite" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:cve-id>CVE-2004-0046</vuln:cve-id>
        <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:21.697-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14164">snapstream-quotation-xss(14164)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9375">9375</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3440">3440</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1008646">1008646</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10575">10575</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107350313917867&amp;w=2">20040106 SnapStream PVS LITE Cross Site Scripting Vulnerabillity</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script or HTML via a GET request containing a terminating '"' (double quote) character.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0045">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:isc:inn:2.4.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:isc:inn:2.4.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0045</vuln:cve-id>
        <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:21.553-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/759020">VU#759020</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9382">9382</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/bugtraq/2004-01/0064.html">20040108 [OpenPKG-SA-2004.001] OpenPKG Security Advisory (inn)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/bugtraq/2004-01/0063.html">20040107 [SECURITY] INN: Buffer overflow in control message handling</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14190">inn-artpost-control-message-bo(14190)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.365791">SSA:2004-014-02</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10578">10578</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the ARTpost function in art.c in the control message handling code for INN 2.4.0 may allow remote attackers to execute arbitrary code.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0044">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:cisco:personal_assistant:1.4%281%29" />
                <cpe-lang:fact-ref name="cpe:/a:cisco:personal_assistant:1.4%282%29" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:cisco:personal_assistant:1.4%281%29</vuln:product>
            <vuln:product>cpe:/a:cisco:personal_assistant:1.4%282%29</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0044</vuln:cve-id>
        <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:21.397-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CISCO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cisco.com/warp/public/707/cisco-sa-20040108-pa.shtml">20040108 Cisco Personal Assistant User Password Bypass Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14172">ciscopersonalassistant-config-file-access(14172)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9384">9384</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3430">3430</vuln:reference>
        </vuln:references>
        <vuln:summary>Cisco Personal Assistant 1.4(1) and 1.4(2) disables password authentication when "Allow Only Cisco CallManager Users" is enabled and the Corporate Directory settings refer to the directory service being used by Cisco CallManager, which allows remote attackers to gain access with a valid username.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0043">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.6.0.1351" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:yahoo:messenger:5.6.0.1351</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0043</vuln:cve-id>
        <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:21.243-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9383">9383</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2004-January/015334.html">20040108 Yahoo Instant Messenger Long Filename Downloading Buffer Overflow</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14171">yahoo-messenger-filename-bo(14171)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008651">1008651</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3437">3437</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10573">10573</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107357996802255&amp;w=2">20040108 Yahoo Instant Messenger Long Filename Downloading Buffer Overflow</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in the download feature.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0042">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:beasts:vsftpd:1.1.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:beasts:vsftpd:1.1.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0042</vuln:cve-id>
        <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:24:55.477-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1008628">1008628</vuln:reference>
        </vuln:references>
        <vuln:summary>vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0041">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mod_auth_shadow:mod_auth_shadow:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:mod_auth_shadow:mod_auth_shadow:1.1" />
                <cpe-lang:fact-ref name="cpe:/a:mod_auth_shadow:mod_auth_shadow:1.2" />
                <cpe-lang:fact-ref name="cpe:/a:mod_auth_shadow:mod_auth_shadow:1.3" />
                <cpe-lang:fact-ref name="cpe:/a:mod_auth_shadow:mod_auth_shadow:1.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mod_auth_shadow:mod_auth_shadow:1.0</vuln:product>
            <vuln:product>cpe:/a:mod_auth_shadow:mod_auth_shadow:1.2</vuln:product>
            <vuln:product>cpe:/a:mod_auth_shadow:mod_auth_shadow:1.1</vuln:product>
            <vuln:product>cpe:/a:mod_auth_shadow:mod_auth_shadow:1.3</vuln:product>
            <vuln:product>cpe:/a:mod_auth_shadow:mod_auth_shadow:1.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0041</vuln:cve-id>
        <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:20.947-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-421">DSA-421</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008675">1008675</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9404">9404</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3454">3454</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10612">10612</vuln:reference>
        </vuln:references>
        <vuln:summary>The mod_auth_shadow module 1.4 and earlier does not properly enforce the expiration of a user account and password, which could allow remote authenticated users to bypass intended access restrictions.</vuln:summary>
    </entry>
    <entry id="CVE-2004-1082">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.11" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.12" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.14" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.17" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.18" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.19" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.20" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.22" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.23" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.24" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.25" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.26" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.27" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.28" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.29" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.4" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.6" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.7::dev" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.9" />
                <cpe-lang:fact-ref name="cpe:/a:apple:apache_mod_digest_apple" />
                <cpe-lang:fact-ref name="cpe:/a:avaya:communication_manager:1.1" />
                <cpe-lang:fact-ref name="cpe:/a:avaya:communication_manager:1.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:avaya:communication_manager:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:avaya:communication_manager:2.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:avaya:intuity_audix_lx" />
                <cpe-lang:fact-ref name="cpe:/a:hp:virtualvault:4.5" />
                <cpe-lang:fact-ref name="cpe:/a:hp:virtualvault:4.6" />
                <cpe-lang:fact-ref name="cpe:/a:hp:virtualvault:4.7" />
                <cpe-lang:fact-ref name="cpe:/a:hp:webproxy:a.02.00" />
                <cpe-lang:fact-ref name="cpe:/a:hp:webproxy:a.02.10" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:http_server:1.3.19" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:avaya:mn100" />
                <cpe-lang:fact-ref name="cpe:/a:avaya:network_routing" />
                <cpe-lang:fact-ref name="cpe:/o:avaya:modular_messaging_message_storage_server:1.1" />
                <cpe-lang:fact-ref name="cpe:/o:avaya:modular_messaging_message_storage_server:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.4" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.5" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:current" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.6" />
                <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.7" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:avaya:communication_manager:1.3.1</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
            <vuln:product>cpe:/a:avaya:mn100</vuln:product>
            <vuln:product>cpe:/a:hp:virtualvault:4.6</vuln:product>
            <vuln:product>cpe:/a:hp:virtualvault:4.5</vuln:product>
            <vuln:product>cpe:/a:hp:virtualvault:4.7</vuln:product>
            <vuln:product>cpe:/a:avaya:network_routing</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.18</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.1</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.17</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
            <vuln:product>cpe:/a:avaya:intuity_audix_lx</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.19</vuln:product>
            <vuln:product>cpe:/o:avaya:modular_messaging_message_storage_server:2.0</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.14</vuln:product>
            <vuln:product>cpe:/a:hp:webproxy:a.02.00</vuln:product>
            <vuln:product>cpe:/o:avaya:modular_messaging_message_storage_server:1.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.9</vuln:product>
            <vuln:product>cpe:/a:avaya:communication_manager:2.0.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.12</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.11</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.6</vuln:product>
            <vuln:product>cpe:/a:apple:apache_mod_digest_apple</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.4</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.7::dev</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0.7</vuln:product>
            <vuln:product>cpe:/a:avaya:communication_manager:2.0</vuln:product>
            <vuln:product>cpe:/o:sco:openserver:5.0.6</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
            <vuln:product>cpe:/a:avaya:communication_manager:1.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.27</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.26</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.25</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.24</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:current</vuln:product>
            <vuln:product>cpe:/a:ibm:http_server:1.3.19</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.29</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.28</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:3.4</vuln:product>
            <vuln:product>cpe:/a:hp:webproxy:a.02.10</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.23</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.22</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:3.5</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.20</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-1082</vuln:cve-id>
        <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:40:19.187-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-17T17:15:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18347">macos-moddigest-response-replay(18347)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/alerts/2004/Dec/1012414.html">1012414</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9571">9571</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/p-049.shtml">P-049</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html">APPLE-SA-2004-12-02</vuln:reference>
        </vuln:references>
        <vuln:summary>mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2085">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:brad_fears:phpcodecabinet:0.1" />
                <cpe-lang:fact-ref name="cpe:/a:brad_fears:phpcodecabinet:0.2" />
                <cpe-lang:fact-ref name="cpe:/a:brad_fears:phpcodecabinet:0.3" />
                <cpe-lang:fact-ref name="cpe:/a:brad_fears:phpcodecabinet:0.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:brad_fears:phpcodecabinet:0.1</vuln:product>
            <vuln:product>cpe:/a:brad_fears:phpcodecabinet:0.4</vuln:product>
            <vuln:product>cpe:/a:brad_fears:phpcodecabinet:0.2</vuln:product>
            <vuln:product>cpe:/a:brad_fears:phpcodecabinet:0.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2085</vuln:cve-id>
        <vuln:published-datetime>2004-02-04T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:09.723-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-25T13:12:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15190">phpcodecabinet-multiple-xss(15190)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9645">9645</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9601">9601</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3887">3887</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3886">3886</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3885">3885</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/project/shownotes.php?release_id=214860">http://sourceforge.net/project/shownotes.php?release_id=214860</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/themes/phpcc/header.php?r1=1.4&amp;r2=1.5">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/themes/phpcc/header.php?r1=1.4&amp;r2=1.5</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/themes/facade/header.php?r1=1.4&amp;r2=1.5">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/themes/facade/header.php?r1=1.4&amp;r2=1.5</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/input.php?r1=1.7&amp;r2=1.8">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/input.php?r1=1.7&amp;r2=1.8</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/comments.php?r1=1.1&amp;r2=1.2">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/comments.php?r1=1.1&amp;r2=1.2</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/category.php?r1=1.4&amp;r2=1.5">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/category.php?r1=1.4&amp;r2=1.5</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/browse.php?r1=1.5&amp;r2=1.6">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/browse.php?r1=1.5&amp;r2=1.6</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/16711">16711</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/16710">16710</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1009012">1009012</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10862">10862</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Brad Fears phpCodeCabinet 0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) the sid parameter to comments.php, (2) the cid, cf, or rfd parameters to category.php, or the cid parameter to (3) input.php, (4) browse.php, (5) themes/facade/header.php, or (6) themes/phpcc/header.php.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2073">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:vserver:linux-vserver:1.20" />
                <cpe-lang:fact-ref name="cpe:/a:vserver:linux-vserver:1.21" />
                <cpe-lang:fact-ref name="cpe:/a:vserver:linux-vserver:1.22" />
                <cpe-lang:fact-ref name="cpe:/a:vserver:linux-vserver:1.23" />
                <cpe-lang:fact-ref name="cpe:/a:vserver:linux-vserver:1.24" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:cve-id>CVE-2004-2073</vuln:cve-id>
        <vuln:published-datetime>2004-02-06T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:07.817-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-25T14:32:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.linux-vserver.org/index.php?page=ChangeLog">http://www.linux-vserver.org/index.php?page=ChangeLog</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15073">linux-vserver-gain-privileges(15073)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9596">9596</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/353003">20040206 Linux 2.4.24 with vserver 1.24 exploit</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3875">3875</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10816">10816</vuln:reference>
        </vuln:references>
        <vuln:summary>Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside the virtual server via a modified chroot-again exploit using the chmod command.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2086">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:6.0" />
                <cpe-lang:fact-ref name="cpe:/a:sambar:sambar_server:6.0:beta3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sambar:sambar_server:6.0</vuln:product>
            <vuln:product>cpe:/a:sambar:sambar_server:6.0:beta3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2086</vuln:cve-id>
        <vuln:published-datetime>2004-02-06T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:09.877-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-25T13:03:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.sambar.com/security.htm">http://www.sambar.com/security.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/5786">5786</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15071">sambar-http-post-bo(15071)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9607">9607</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULN-DEV</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/82/353087">20040207 Sambar 6.0 stack overflow</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1008979">1008979</vuln:reference>
        </vuln:references>
        <vuln:summary>Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a long query parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2089">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:matrix:matrix_ftp_server" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:cve-id>CVE-2004-2089</vuln:cve-id>
        <vuln:published-datetime>2004-02-06T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:10.330-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-25T12:47:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15075">matrixftp-login-list-dos(15075)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1008970">1008970</vuln:reference>
        </vuln:references>
        <vuln:summary>Matrix FTP Server allows remote attackers to cause a denial of service (crash) by logging in using four spaces as the username and password and then issuing a LIST command.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2084">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:jshop_e-commerce:jshop_professional:3.0" />
                <cpe-lang:fact-ref name="cpe:/a:jshop_e-commerce:jshop_professional:3.1" />
                <cpe-lang:fact-ref name="cpe:/a:jshop_e-commerce:jshop_professional:3.2" />
                <cpe-lang:fact-ref name="cpe:/a:jshop_e-commerce:jshop_professional:3.3" />
                <cpe-lang:fact-ref name="cpe:/a:jshop_e-commerce:jshop_professional:3.4" />
                <cpe-lang:fact-ref name="cpe:/a:jshop_e-commerce:jshop_server:1.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:jshop_e-commerce:jshop_server:1.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:jshop_e-commerce:jshop_server:1.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:jshop_e-commerce:jshop_server:1.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:jshop_e-commerce:jshop_server:1.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:jshop_e-commerce:jshop_server:1.2.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:jshop_e-commerce:jshop_server:1.0.2</vuln:product>
            <vuln:product>cpe:/a:jshop_e-commerce:jshop_server:1.0.1</vuln:product>
            <vuln:product>cpe:/a:jshop_e-commerce:jshop_server:1.0.4</vuln:product>
            <vuln:product>cpe:/a:jshop_e-commerce:jshop_server:1.0.3</vuln:product>
            <vuln:product>cpe:/a:jshop_e-commerce:jshop_server:1.2.0</vuln:product>
            <vuln:product>cpe:/a:jshop_e-commerce:jshop_professional:3.0</vuln:product>
            <vuln:product>cpe:/a:jshop_e-commerce:jshop_server:1.1.0</vuln:product>
            <vuln:product>cpe:/a:jshop_e-commerce:jshop_professional:3.2</vuln:product>
            <vuln:product>cpe:/a:jshop_e-commerce:jshop_professional:3.1</vuln:product>
            <vuln:product>cpe:/a:jshop_e-commerce:jshop_professional:3.4</vuln:product>
            <vuln:product>cpe:/a:jshop_e-commerce:jshop_professional:3.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2084</vuln:cve-id>
        <vuln:published-datetime>2004-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:09.550-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-25T13:18:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15100">jshop-searchphp-xss(15100)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3889">3889</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.systemsecure.org/advisories/ssadvisory09022004.php">http://www.systemsecure.org/advisories/ssadvisory09022004.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9609">9609</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1008988">1008988</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10825">10825</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in search.php in JShop E-Commerce Server allows remote attackers to inject arbitrary web script or HTML via the xSearch parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2090">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp4" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp4</vuln:product>
            <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2090</vuln:cve-id>
        <vuln:published-datetime>2004-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:10.487-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-25T12:43:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15078">ie-error-obtain-information(15078)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9611">9611</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10820">10820</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016881.html">20040207 (no subject)</vuln:reference>
        </vuln:references>
        <vuln:summary>Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist.</vuln:summary>
    </entry>
    <entry id="CVE-2004-1244">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_player:9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:windows_media_player:9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-1244</vuln:cve-id>
        <vuln:published-datetime>2004-02-08T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:29:40.757-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-20T10:50:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:2379" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2379" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1568" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1568" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1306" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1306" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/259890">VU#259890</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19096">win-ms05kb890261-update(19096)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MS</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.microsoft.com/technet/security/bulletin/MS05-009.mspx">MS05-009</vuln:reference>
        </vuln:references>
        <vuln:summary>Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."</vuln:summary>
    </entry>
    <entry id="CVE-2004-2077">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:nadeo:game_engine" />
                <cpe-lang:fact-ref name="cpe:/a:nadeo:trackmania" />
                <cpe-lang:fact-ref name="cpe:/a:nadeo:virtual_skipper:3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:nadeo:trackmania</vuln:product>
            <vuln:product>cpe:/a:nadeo:game_engine</vuln:product>
            <vuln:product>cpe:/a:nadeo:virtual_skipper:3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2077</vuln:cve-id>
        <vuln:published-datetime>2004-02-08T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:08.440-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-25T13:59:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15081">trackmania-dos(15081)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9604">9604</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/353226">20040209 Re: TrackMania Demo Denial of Service</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/353182">20040208 TrackMania Demo Denial of Service</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securiteinfo.com/attaques/hacking/trackmaniados.shtml">http://www.securiteinfo.com/attaques/hacking/trackmaniados.shtml</vuln:reference>
        </vuln:references>
        <vuln:summary>Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed data to TCP port 2350, possibly due to long values or incorrect size fields.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2077">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:nadeo:game_engine" />
                <cpe-lang:fact-ref name="cpe:/a:nadeo:trackmania" />
                <cpe-lang:fact-ref name="cpe:/a:nadeo:virtual_skipper:3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:nadeo:trackmania</vuln:product>
            <vuln:product>cpe:/a:nadeo:game_engine</vuln:product>
            <vuln:product>cpe:/a:nadeo:virtual_skipper:3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2077</vuln:cve-id>
        <vuln:published-datetime>2004-02-08T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:08.440-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-25T13:59:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15081">trackmania-dos(15081)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9604">9604</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/353226">20040209 Re: TrackMania Demo Denial of Service</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/353182">20040208 TrackMania Demo Denial of Service</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securiteinfo.com/attaques/hacking/trackmaniados.shtml">http://www.securiteinfo.com/attaques/hacking/trackmaniados.shtml</vuln:reference>
        </vuln:references>
        <vuln:summary>Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed data to TCP port 2350, possibly due to long values or incorrect size fields.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2078">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:red-m:red-alert:2.7.5_v3.1_build_24" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:red-m:red-alert:2.7.5_v3.1_build_24</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2078</vuln:cve-id>
        <vuln:published-datetime>2004-02-09T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:08.597-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-25T13:45:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1009001">1009001</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15086">redalert-long-request-dos(15086)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9618">9618</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/353211">20040209 Red-M Red-Alert Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securiteam.com/securitynews/5SP0C0KC0A.html">http://www.securiteam.com/securitynews/5SP0C0KC0A.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3891">3891</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10832">10832</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://genhex.org/releases/031003.txt">http://genhex.org/releases/031003.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=107635119005407&amp;w=2">20040209 Red-M Red-Alert Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:summary>Red-M Red-Alert 2.7.5 with software 3.1 build 24 allows remote attackers to cause a denial of service (reboot and loss of logged events) via a long request to TCP port 80, possibly triggering a buffer overflow.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2079">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:red-m:red-alert:2.7.5_v3.1_build_24" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:red-m:red-alert:2.7.5_v3.1_build_24</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2079</vuln:cve-id>
        <vuln:published-datetime>2004-02-09T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:32:55.523-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-25T13:41:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1009001">1009001</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15088">redalert-gain-access(15088)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9618">9618</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/353211">20040209 Red-M Red-Alert Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securiteam.com/securitynews/5SP0C0KC0A.html">http://www.securiteam.com/securitynews/5SP0C0KC0A.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://genhex.org/releases/031003.txt">http://genhex.org/releases/031003.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3952">3952</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=107635119005407&amp;w=2">20040209 Red-M Red-Alert Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:summary>Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2080">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:red-m:red-alert:2.7.5_v3.1_build_24" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:red-m:red-alert:2.7.5_v3.1_build_24</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2080</vuln:cve-id>
        <vuln:published-datetime>2004-02-09T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:32:55.617-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-25T13:34:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1009001">1009001</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15089">redalert-bypass-security(15089)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9618">9618</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/353211">20040209 Red-M Red-Alert Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securiteam.com/securitynews/5SP0C0KC0A.html">http://www.securiteam.com/securitynews/5SP0C0KC0A.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://genhex.org/releases/031003.txt">http://genhex.org/releases/031003.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3953">3953</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=107635119005407&amp;w=2">20040209 Red-M Red-Alert Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:summary>Red-M Red-Alert 2.7.5 with software 3.1 build 24 converts multiple spaces in a Service Set Identifier (SSID) to a single space, which prevents Red-Alert from correctly identifying the SSID.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2092">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ca:inoculateit:6.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ca:inoculateit:6.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2092</vuln:cve-id>
        <vuln:published-datetime>2004-02-09T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:10.817-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-25T12:33:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15103">etrust-inoculateit-insecure-permissions(15103)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9616">9616</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3896">3896</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10833">10833</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107635584431518&amp;w=2">20040209 [local problems] eTrust Virus Protection 6.0 InoculateIT for linux</vuln:reference>
        </vuln:references>
        <vuln:summary>eTrust InoculateIT for Linux 6.0 uses insecure permissions for multiple files and directories, including the application's registry and tmp directories, which allows local users to delete, modify, or examine sensitive information.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2093">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:gnu:rsync:2.5.7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:cve-id>CVE-2004-2093</vuln:cve-id>
        <vuln:published-datetime>2004-02-09T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:10.973-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-25T12:48:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15108">linux-rsync-opensocketout-bo(15108)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULN-DEV</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vuln-dev/2004-q1/0091.html">20040209 rsync &lt;= 2.5.7 local buffer overflow (no root today:)</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PROXY environment variable.  NOTE: since rsync is not setuid, this issue does not provide any additional privileges beyond those that are already available to the user.  Therefore this issue may be REJECTED in the future.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2091">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:microsoft:baseline_security_analyzer:1.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:baseline_security_analyzer:1.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2091</vuln:cve-id>
        <vuln:published-datetime>2004-02-10T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:10.660-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-25T12:37:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9634">9634</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/353324">20040210 Another Low Blow From Microsoft: MBSA Failure!</vuln:reference>
        </vuln:references>
        <vuln:summary>Microsoft Baseline Security Analyzer (MBSA) 1.2 does not correctly identify systems that have been patched but remain vulnerable to exploit until the system is rebooted, possibly giving the administrator a false sense of security.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2083">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0.1::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0.2::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0.3::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0_beta1::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0_beta2::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.10" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.11" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.11b" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.11j" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.20" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.20_beta1_build2981" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.21" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.22" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.23" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0_beta2::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.11j</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0.2::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.20_beta1_build2981</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0.1::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.11b</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.11</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.23</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0_beta1::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.10</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.22</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.21</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.20</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0.3::win32</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2083</vuln:cve-id>
        <vuln:published-datetime>2004-02-11T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:09.363-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.6</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-25T13:19:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9640">9640</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/Internet_Explorer_File_Download_Extension_Spoofing_Test/">http://secunia.com/Internet_Explorer_File_Download_Extension_Spoofing_Test/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10760">10760</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/21698">opera-cslid-extension-spoof(21698)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3917">3917</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.opera.com/docs/changelogs/windows/750b1/">http://www.opera.com/docs/changelogs/windows/750b1/</vuln:reference>
        </vuln:references>
        <vuln:summary>Opera Web Browser 7.0 through 7.23 allows remote attackers to trick users into executing a malicious file by embedding a CLSID in the file name, which causes the malicious file to appear as a trusted file type, aka "File Download Extension Spoofing."</vuln:summary>
    </entry>
    <entry id="CVE-2004-2088">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sophos:sophos_anti-virus:3.4.6" />
                <cpe-lang:fact-ref name="cpe:/a:sophos:sophos_anti-virus:3.78" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sophos:sophos_anti-virus:3.4.6</vuln:product>
            <vuln:product>cpe:/a:sophos:sophos_anti-virus:3.78</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2088</vuln:cve-id>
        <vuln:published-datetime>2004-02-12T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:10.177-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-25T12:51:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15192">sophos-email-virus-undetected(15192)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.sophos.com/support/news/#mime-378">http://www.sophos.com/support/news/#mime-378</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9650">9650</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1009042">1009042</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10855">10855</vuln:reference>
        </vuln:references>
        <vuln:summary>Sophos Anti-Virus 3.78 allows remote attackers to bypass virus scanning by using a qmail generated Delivery Status Notification (DSN) where the original email is not included in the bounce message.</vuln:summary>
    </entry>
    <entry id="CVE-2004-2082">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:karjasoft:sami_ftp_server:1.1.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:karjasoft:sami_ftp_server:1.1.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2082</vuln:cve-id>
        <vuln:published-datetime>2004-02-13T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:09.207-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-25T13:24:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.karja.com/samiftp/news.html">http://www.karja.com/samiftp/news.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15204">sami-cd-get-dos(15204)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9657">9657</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/353753">20040213 Sami FTP Server 1.1.3 multiple vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:summary>The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsystem.exe crash) via a GET request wit a large number of leading "/" (slash) characters.</vuln:summary>
    </entry>
    <entry id="CVE-2004-1180">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::woody" />
                <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.0" />
                <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.0::amd64" />
                <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.1" />
                <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.1::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1" />
                <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1::x86_64" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:10.0::amd64</vuln:product>
            <vuln:product>cpe:/o:sun:solaris</vuln:product>
            <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:10.1</vuln:product>
            <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:10.0</vuln:product>
            <vuln:product>cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1</vuln:product>
            <vuln:product>cpe:/o:debian:debian_linux:3.0::woody</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:9.0</vuln:product>
            <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:10.1::x86_64</vuln:product>
            <vuln:product>cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1::x86_64</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-1180</vuln:cve-id>
        <vuln:published-datetime>2004-02-16T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:29:26.947-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-20T10:07:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-678">DSA-678</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:039">MDKSA-2005:039</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14309">14309</vuln:reference>
        </vuln:references>
        <vuln:summary>Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows remote attackers to cause a denial of service (application crash).</vuln:summary>
    </entry>
    <entry id="CVE-2004-0001">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0001</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:16.257-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:868" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:868" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/337238">VU#337238</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-017.html">RHSA-2004:017</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14888">linux-ptrace-gain-privilege(14888)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9429">9429</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200402-06.xml">GLSA-200402-06</vuln:reference>
        </vuln:references>
        <vuln:summary>Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0004">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:openca:openca:0.9.1.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:openca:openca:0.9.1.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0004</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:16.853-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/336446">VU#336446</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9435">9435</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openca.org/news/CAN-2004-0004.txt">http://www.openca.org/news/CAN-2004-0004.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14847">openca-improper-signature-verification(14847)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3615">3615</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107427313700554&amp;w=2">20040116 [OpenCA Advisory] Vulnerability in signature verification</vuln:reference>
        </vuln:references>
        <vuln:summary>The libCheckSignature function in crypto-utils.lib for OpenCA 0.9.1.6 and earlier only compares the serial of the signer's certificate and the one in the database, which can cause OpenCA to incorrectly accept a signature if the certificate's chain is trusted by OpenCA's chain directory, allowing remote attackers to spoof requests from other users.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0054">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3t" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0s" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0t" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1e" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1t" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2s" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2t" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:cisco:ios:12.2</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.1</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.2t</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.2s</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.1t</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.1e</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0s</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.0t</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:11.3t</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0054</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-03-04T00:21:09.437-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:4884" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4884" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/749342">VU#749342</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-2004-01.html">CA-2004-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CISCO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cisco.com/warp/public/707/cisco-sa-20040113-h323.shtml">20040113 Vulnerabilities in H.323 Message Processing</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.uniras.gov.uk/vuls/2004/006489/h323.htm">http://www.uniras.gov.uk/vuls/2004/006489/h323.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008685">1008685</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9406">9406</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0055">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.6.2" />
                <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.7" />
                <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.7.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:lbl:tcpdump:3.6.2</vuln:product>
            <vuln:product>cpe:/a:lbl:tcpdump:3.7</vuln:product>
            <vuln:product>cpe:/a:lbl:tcpdump:3.7.1</vuln:product>
            <vuln:product>cpe:/a:lbl:tcpdump:3.5.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0055</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-02-06T00:29:19.907-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:853" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:853" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:850" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:850" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/955526">VU#955526</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/7090">7090</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-008.html">RHSA-2004:008</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00015.html">[fedora-announce-list] 20040311 Re: [SECURITY] Fedora Core 1 Update: tcpdump-3.7.2-8.fc1.1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00009.html">FEDORA-2004-092</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00006.html">FEDORA-2004-090</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-425">DSA-425</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/12179/">12179</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/11032/">11032</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/11022">11022</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10718">10718</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10652">10652</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10644">10644</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10639">10639</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10636">10636</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://lwn.net/Alerts/66445/">2004-0004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc">20040103-01-U</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SCO</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.9/SCOSA-2004.9.txt">SCOSA-2004.9</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CALDERA</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2004-008.0.txt">CSSA-2004-008.0</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008735">1008735</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html">FLSA:1222</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:008">MDKSA-2004:008</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=tcpdump-workers&amp;m=107325073018070&amp;w=2">[tcpdump-workers] multiple vulnerabilities in tcpdump 3.8.1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577418225627&amp;w=2">20040131 [FLSA-2004:1222] Updated tcpdump resolves security vulnerabilites (resend with correct paths)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000832">CLSA-2003:832</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</vuln:reference>
        </vuln:references>
        <vuln:summary>The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0056">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:nortel:business_communications_manager" />
                <cpe-lang:fact-ref name="cpe:/h:nortel:802.11_wireless_ip_gateway" />
                <cpe-lang:fact-ref name="cpe:/h:nortel:succession_communication_server_1000" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:nortel:802.11_wireless_ip_gateway</vuln:product>
            <vuln:product>cpe:/a:nortel:business_communications_manager</vuln:product>
            <vuln:product>cpe:/h:nortel:succession_communication_server_1000</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0056</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:23.210-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/749342">VU#749342</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-2004-01.html">CA-2004-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.uniras.gov.uk/vuls/2004/006489/h323.htm">http://www.uniras.gov.uk/vuls/2004/006489/h323.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008687">1008687</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9406">9406</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple vulnerabilities in the H.323 protocol implementation for Nortel Networks Business Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, and 802.11 Wireless IP Gateway allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0057">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.8.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:lbl:tcpdump:3.8.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0057</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-02-20T00:29:04.030-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:854" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:854" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:851" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:851" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/174086">VU#174086</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9423">9423</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-007.html">RHSA-2004:007</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-425">DSA-425</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14837">tcpdump-rawprint-isakmp-dos(14837)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/350238/30/21640/threaded">20040119 [ESA-20040119-002] 'tcpdump' multiple vulnerabilities.</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-008.html">RHSA-2004:008</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00015.html">[fedora-announce-list] 20040311 Re: [SECURITY] Fedora Core 1 Update: tcpdump-3.7.2-8.fc1.1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00009.html">FEDORA-2004-092</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00006.html">FEDORA-2004-090</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/12179/">12179</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/11032/">11032</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/11022">11022</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10718">10718</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10668">10668</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10652">10652</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10644">10644</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10639">10639</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10636">10636</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=tcpdump-workers&amp;m=107325073018070&amp;w=2">[tcpdump-workers] multiple vulnerabilities in tcpdump 3.8.1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>ENGARDE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lwn.net/Alerts/66805/">ESA-20040119-002</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://lwn.net/Alerts/66445/">2004-0004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc">20040103-01-U</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SCO</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.9/SCOSA-2004.9.txt">SCOSA-2004.9</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CALDERA</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2004-008.0.txt">CSSA-2004-008.0</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008716">1008716</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html">FLSA:1222</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:008">MDKSA-2004:008</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577418225627&amp;w=2">20040131 [FLSA-2004:1222] Updated tcpdump resolves security vulnerabilites (resend with correct paths)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</vuln:reference>
        </vuln:references>
        <vuln:summary>The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0058">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.9.9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:linux_kernel:2.0.9.9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0058</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:23.523-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14214">antivir-tmpfile-insecure(14214)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008702">1008702</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3496">3496</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10620">10620</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107402026023763&amp;w=2">20040113 symlink vul for Antivir / Linux Version 2.0.9-9 (maybe lower)</vuln:reference>
        </vuln:references>
        <vuln:summary>Antivir / Linux 2.0.9-9, and possibly earlier versions, allows local users to overwrite arbitrary files via a symlink attack on the .pid_antivir_$$ temporary file.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0059">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:lionmax_software:www_file_share_pro:2.42" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:lionmax_software:www_file_share_pro:2.42</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0059</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:23.663-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008779">1008779</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0060">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:lionmax_software:www_file_share_pro:2.42" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:lionmax_software:www_file_share_pro:2.42</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0060</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:23.803-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008779">1008779</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</vuln:reference>
        </vuln:references>
        <vuln:summary>WWW File Share Pro 2.42 and earlier allows remote attackers to cause a denial of service (crash) via a large POST request.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0061">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:lionmax_software:www_file_share_pro:2.42" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:lionmax_software:www_file_share_pro:2.42</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0061</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:23.960-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008779">1008779</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</vuln:reference>
        </vuln:references>
        <vuln:summary>WWW File Share Pro 2.42 and earlier allows remote attackers to bypass directory access restrictions via (1) a URL with a trailing . (dot), or (2) a URI with a leading slash or backslash character.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0062">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:fishnet:fishcart:3.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:fishnet:fishcart:3.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0062</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:24:59.557-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411850203994&amp;w=2">20040114 FishCart Integer Overflow / Rounding Error</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008731">1008731</vuln:reference>
        </vuln:references>
        <vuln:summary>Integer overflow in the rnd arithmetic rounding function for various versions of FishCart before 3.1 allows remote attackers to "cause negative totals" via an order with a large quantity.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0063">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ncipher:payshield_spp_library:1.3.12" />
                <cpe-lang:fact-ref name="cpe:/a:ncipher:payshield_spp_library:1.5.18" />
                <cpe-lang:fact-ref name="cpe:/a:ncipher:payshield_spp_library:1.6.18" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ncipher:payshield_spp_library:1.3.12</vuln:product>
            <vuln:product>cpe:/a:ncipher:payshield_spp_library:1.6.18</vuln:product>
            <vuln:product>cpe:/a:ncipher:payshield_spp_library:1.5.18</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0063</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:24.290-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ncipher.com/support/advisories/advisory8_payshield.html">http://www.ncipher.com/support/advisories/advisory8_payshield.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14832">payshield-incorrect-request-verification(14832)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9422">9422</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3537">3537</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411819503569&amp;w=2">20040114 nCipher Advisory #8: payShield library may verify bad requests</vuln:reference>
        </vuln:references>
        <vuln:summary>The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g. by accepting an invalid PIN number.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0064">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:suse:suse_linux:9.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0064</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:24.430-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9411">9411</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008703">1008703</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3460">3460</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10623">10623</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107402658600437&amp;w=2">20040113 SuSE linux 9.0 YaST config Skribt [exploit]</vuln:reference>
        </vuln:references>
        <vuln:summary>The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0065">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.65" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpgedview:phpgedview:2.65</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0065</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:24.587-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2">20040112 More phpGedView Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/11925">11925</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/11910">11910</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2) placelist.php.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0066">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.65" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpgedview:phpgedview:2.65</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0066</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:24.727-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2">20040112 More phpGedView Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14215">phpgedview-path-disclosure(14215)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3464">3464</vuln:reference>
        </vuln:references>
        <vuln:summary>phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0067">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.65" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpgedview:phpgedview:2.65</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0067</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T00:28:44.907-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2">20040112 More phpGedView Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/36285">phpgedview-login-xss(36285)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14212">phpgedview-multiple-xss(14212)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/11907">11907</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/11906">11906</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/11905">11905</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/11904">11904</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/11903">11903</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/11894">11894</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/11891">11891</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/11890">11890</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/11888">11888</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/11882">11882</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/11880">11880</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/11868">11868</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/477881/100/0/threaded">20070827 PhpGedView login page multiple XSS</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3479">3479</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3478">3478</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3477">3477</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3476">3476</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3475">3475</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3474">3474</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3473">3473</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/2995">ADV-2007-2995</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1018613">1018613</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26628">26628</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php.  NOTE: some aspects of vector 10 were later reported to affect 4.1.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0068">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpdig.net:phpdig:1.6.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpdig.net:phpdig:1.6.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0068</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:25.023-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9424">9424</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.phpdig.net/showthread.php?s=58bcc71c822830ec3bbdaae6d56846e0&amp;threadid=393">http://www.phpdig.net/showthread.php?s=58bcc71c822830ec3bbdaae6d56846e0&amp;threadid=393</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107412194008671&amp;w=2">20040114 PhpDig 1.6.x: remote command execution</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14826">phpdig-config-file-include(14826)</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file inclusion vulnerability in config.php for PhpDig 1.6.5 and earlier allows remote attackers to execute arbitrary PHP code by modifying the $relative_script_path parameter to reference a URL on a remote web server that contains the code.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0069">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:hd_soft:windows_ftp_server:1.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:hd_soft:windows_ftp_server:1.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0069</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:25.180-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9385">9385</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107401398014761&amp;w=2">20040113 exploit for HD Soft Windows FTP Server 1.6</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107367110805273&amp;w=2">20040108 Windows FTP Server Format String Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008658">1008658</vuln:reference>
        </vuln:references>
        <vuln:summary>Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0070">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:visualshapers:ezcontents</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0070</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:25.337-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14199">ezcontents-php-file-include(14199)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9396">9396</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/6878">6878</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ezcontents.org/forum/viewtopic.php?t=361">http://www.ezcontents.org/forum/viewtopic.php?t=361</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392588915627&amp;w=2">20040110 Remote Code Execution in ezContents</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the link parameter to reference a URL on a remote web server that contains the code.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0071">
        <vuln:cve-id>CVE-2004-0071</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14203">manpagelookup-directory-traversal(14203)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9395">9395</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392764118403&amp;w=2">20040110 PHP Manpage lookup directory transversal / file disclosing</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008689">1008689</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0072">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:accipiter:accipiter_direct_server:6.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:accipiter:accipiter_direct_server:6.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0072</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:25.570-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9389">9389</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14198">accipterdirectserver-directory-traversal(14198)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392576215418&amp;w=2">20040109 Directory Traversal in Accipiter Direct Server 6.0</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0274.html">20040109 Directory Traversal in Accipiter Direct Server 6.0</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3433">3433</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10600">10600</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via encoded \.. (backslash .., "%5c%2e%2e") sequences in an HTTP request.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0073">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:stoitsov:easydynamicpages:2.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:stoitsov:easydynamicpages:2.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0073</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:25.727-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9338">9338</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14136">easydynamicpages-php-file-include(14136)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3408">3408</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3318">3318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1008584">1008584</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10535">10535</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107307457327707&amp;w=2">20040102 include() vuln in EasyDynamicPages v.2.0</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to execute arbitrary PHP code by modifying the edp_relative_path parameter to reference a URL on a remote web server that contains a malicious serverdata.php script.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0074">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:michael_bischoff:xsok:1.02" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:michael_bischoff:xsok:1.02</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0074</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:25.867-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9341">9341</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14910">xsok-lang-bo(14910)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14906">xsok-long-xsokdir-bo(14906)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9352">9352</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107332542918529&amp;w=2">20040103 xsok local games exploit (2)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107307407027259&amp;w=2">20040102 xsok local games exploit</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, or (2) a long -xsokdir command line argument, a different vulnerability than CVE-2003-0949.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0049">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:helix_universal_mobile_server:10.1.1.120" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:helix_universal_server:9.0.2.881" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:realnetworks:helix_universal_server:9.0.2.881</vuln:product>
            <vuln:product>cpe:/a:realnetworks:helix_universal_mobile_server:10.1.1.120</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0049</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:21.993-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication approximated="true">SINGLE_INSTANCE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://service.real.com/help/faq/security/040112_dos/">http://service.real.com/help/faq/security/040112_dos/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9421">9421</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://service.real.com/help/faq/security/security022604.html">http://service.real.com/help/faq/security/security022604.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/357834">20040318 ptl-2004-02: RealNetworks Helix Server 9 Administration Server Buffer Overflow</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://seclists.org/lists/vulnwatch/2004/Jan-Mar/0057.html">20040318 ptl-2004-02: RealNetworks Helix Server 9 Administration Server Buffer Overflow</vuln:reference>
        </vuln:references>
        <vuln:summary>Helix Universal Server/Proxy 9 and Mobile Server 10 allow remote attackers to cause a denial of service via certain HTTP POST messages to the Administration System port.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0095">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:3.6.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:3.6.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0095</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:31.240-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9476">9476</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://download.nai.com/products/patches/ePO/v3.1.0/EPO3013.zip">http://download.nai.com/products/patches/ePO/v3.1.0/EPO3013.zip</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14989">epolicy-contentlength-post-dos(14989)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3744">3744</vuln:reference>
        </vuln:references>
        <vuln:summary>McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0091">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.0_beta_2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:jelsoft:vbulletin:3.0_beta_2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0091</vuln:cve-id>
        <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:25:06.507-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1008780">1008780</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULN-DEV</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107488880317647&amp;w=2">20040123 RE: vBulletin Security Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULN-DEV</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107478592401619&amp;w=2">20040120 Re: vBulletin Security Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULN-DEV</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107462499927040&amp;w=2">20040120 vBulletin Security Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107462349324945&amp;w=2">20040120 vBulletin Security Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:summary>** DISPUTED **  NOTE: this issue has been disputed by the vendor.  Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter.  NOTE: the vendor has disputed this issue, saying "There is no hidden field called 'reg_site', nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed.  We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft."</vuln:summary>
    </entry>
    <entry id="CVE-2004-2136">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-2136</vuln:cve-id>
        <vuln:published-datetime>2004-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:43:18.143-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-01T09:57:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securiteam.com/exploits/5UP0P1PFPM.html">http://www.securiteam.com/exploits/5UP0P1PFPM.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://mareichelt.de/pub/notmine/diskenc.pdf">http://mareichelt.de/pub/notmine/diskenc.pdf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=107719798631935&amp;w=2">[linux-kernel] 20040219 Re: Oopsing cryptoapi (or loop device?) on 2.6.*</vuln:reference>
        </vuln:references>
        <vuln:summary>dm-crypt on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV computation" weaknesses that allow watermarked files to be detected without decryption.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0466">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:openconnect:webconnect:6.4.4" />
                <cpe-lang:fact-ref name="cpe:/a:openconnect:webconnect:6.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:openconnect:webconnect:6.5</vuln:product>
            <vuln:product>cpe:/a:openconnect:webconnect:6.4.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0466</vuln:cve-id>
        <vuln:published-datetime>2004-02-21T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:38:29.660-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-15T10:59:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/JSHA-69FVMM">http://www.kb.cert.org/vuls/id/JSHA-69FVMM</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/552561">VU#552561</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19393">webconnect-device-name-dos(19393)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14006/">14006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cirt.dk/advisories/cirt-29-advisory.pdf">http://www.cirt.dk/advisories/cirt-29-advisory.pdf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910838600145&amp;w=2">20050220 The WebConnect 6.4.4 and 6.5 contains several vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:summary>WebConnect 6.5, 6.4.4, and possibly earlier versions allows remote attackers to cause a denial of service (hang) via a URL containing an MS-DOS device name such as (1) AUX, (2) CON, (3) PRN, (4) COM1, or (5) LPT1.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0322">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:xmb_forum:xmb:1.8" />
                <cpe-lang:fact-ref name="cpe:/a:xmb_forum:xmb:1.8_sp1" />
                <cpe-lang:fact-ref name="cpe:/a:xmb_forum:xmb:1.8_sp2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:xmb_forum:xmb:1.8</vuln:product>
            <vuln:product>cpe:/a:xmb_forum:xmb:1.8_sp2</vuln:product>
            <vuln:product>cpe:/a:xmb_forum:xmb:1.8_sp1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0322</vuln:cve-id>
        <vuln:published-datetime>2004-02-23T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:38:07.583-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-15T10:15:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15292">xmb-multiple-scripts-xss(15292)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9726">9726</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756526625179&amp;w=2">20040223 [waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8 Partagium Final SP2</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15294">xmb-bbcode-execute-code(15294)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.xmbforum.com/community/boards/viewthread.php?tid=746859">http://www.xmbforum.com/community/boards/viewthread.php?tid=746859</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/bugtraq/2004-02/0645.html">20040225 Re: [waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8 Partagium Final SP2</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users via the (1) member parameter in member.php, (2) uid parameter in u2uadmin.php, (3) user parameter in editprofile.php, (4) an onmouseover event in an align tag when bbcode is allowed, or (5) img tag where bbcode is allowed.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0324">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:confirm:confirm:0.50" />
                <cpe-lang:fact-ref name="cpe:/a:confirm:confirm:0.51" />
                <cpe-lang:fact-ref name="cpe:/a:confirm:confirm:0.52" />
                <cpe-lang:fact-ref name="cpe:/a:confirm:confirm:0.53" />
                <cpe-lang:fact-ref name="cpe:/a:confirm:confirm:0.54" />
                <cpe-lang:fact-ref name="cpe:/a:confirm:confirm:0.55" />
                <cpe-lang:fact-ref name="cpe:/a:confirm:confirm:0.60" />
                <cpe-lang:fact-ref name="cpe:/a:confirm:confirm:0.61" />
                <cpe-lang:fact-ref name="cpe:/a:confirm:confirm:0.62" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:confirm:confirm:0.60</vuln:product>
            <vuln:product>cpe:/a:confirm:confirm:0.61</vuln:product>
            <vuln:product>cpe:/a:confirm:confirm:0.50</vuln:product>
            <vuln:product>cpe:/a:confirm:confirm:0.51</vuln:product>
            <vuln:product>cpe:/a:confirm:confirm:0.52</vuln:product>
            <vuln:product>cpe:/a:confirm:confirm:0.62</vuln:product>
            <vuln:product>cpe:/a:confirm:confirm:0.53</vuln:product>
            <vuln:product>cpe:/a:confirm:confirm:0.54</vuln:product>
            <vuln:product>cpe:/a:confirm:confirm:0.55</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0324</vuln:cve-id>
        <vuln:published-datetime>2004-02-23T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:38:07.897-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-15T10:27:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15290">confirm-header-gain-access(15290)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9728">9728</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107757320401858&amp;w=2">20040223 Lam3rZ Security Advisory #3/2004: A bug in Confirm leads to remote command execution</vuln:reference>
        </vuln:references>
        <vuln:summary>Confirm 0.62 and earlier could allow remote attackers to execute arbitrary code via an e-mail header that contains shell metacharacters such as ", `, |, ;, or $.</vuln:summary>
    </entry>
    <entry id="CVE-2004-1360">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:cve-id>CVE-2004-1360</vuln:cve-id>
        <vuln:published-datetime>2004-02-27T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:29:58.773-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-22T10:50:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1732" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1732" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/412566">VU#412566</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15331">solaris-covfix-gain-privileges(15331)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/o-089.shtml">O-089</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AUSCERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.auscert.org.au/render.html?it=3902">ESB-2004.0169</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57509-1">57509</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10991">10991</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/displayvuln.php?osvdb_id=4071">4071</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9759">9759</vuln:reference>
        </vuln:references>
        <vuln:summary>Unknown vulnerability in conv_fix in Sun Solaris 7 through 9, when invoked by conv_lpd, allows local users to overwrite arbitrary files.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0944">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:mitel:mitel_3300_integrated_communication_platform" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:cve-id>CVE-2004-0944</vuln:cve-id>
        <vuln:published-datetime>2004-02-28T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:39:52.873-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-17T13:56:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.niscc.gov.uk/niscc/docs/re-20050228-00178.pdf?lang=en">http://www.niscc.gov.uk/niscc/docs/re-20050228-00178.pdf?lang=en</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mitel.com/DocController?documentId=14223">http://www.mitel.com/DocController?documentId=14223</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.corsaire.com/advisories/c040817-002.txt">http://www.corsaire.com/advisories/c040817-002.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 generates easily predictable web session IDs, which allows remote attackers to hijack other sessions via the parentsessionid cookie.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0092">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0092</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:25:06.587-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9504">9504</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</vuln:reference>
        </vuln:references>
        <vuln:summary>Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0080">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:util-linux:2.11" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:andries_brouwer:util-linux:2.11</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0080</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:28.070-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/801526">VU#801526</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-056.html">RHSA-2004:056</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9558">9558</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15016">utillinux-information-leak(15016)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3796">3796</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200404-06.xml">GLSA-200404-06</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10773">10773</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108144719532385&amp;w=2">20040408 LNSA-#2004-0010: login may leak sensitive data</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108077689801698&amp;w=2">20040331 OpenLinux: util-linux could leak sensitive data</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20040406-01-U">20040406-01-U</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc">20040201-01-U</vuln:reference>
        </vuln:references>
        <vuln:summary>The login program in util-linux 2.11 and earlier uses a pointer after it has been freed and reallocated, which could cause login to leak sensitive data.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0114">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2" />
                <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:openbsd:openbsd:2.6</vuln:product>
            <vuln:product>cpe:/o:netbsd:netbsd:1.3</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0114</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:34.490-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15061">bsd-shmat-gain-privileges(15061)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9586">9586</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FREEBSD</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:02.shmat.asc">FreeBSD-SA-04:02</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.pine.nl/press/pine-cert-20040201.txt">http://www.pine.nl/press/pine-cert-20040201.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107608375207601&amp;w=2">20040205 [PINE-CERT-20040201] reference count overflow in shmat()</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3836">3836</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openbsd.org/errata33.html#sysvshm">http://www.openbsd.org/errata33.html#sysvshm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>NETBSD</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-004.txt.asc">NetBSD-SA2004-004</vuln:reference>
        </vuln:references>
        <vuln:summary>The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment's reference count when the vm_map_find function fails, which could allow local users to gain read or write access to a portion of kernel memory and gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0115">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:microsoft:virtual_pc:6.0::mac" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:virtual_pc:6.1::mac" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:virtual_pc:6.2::mac" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:virtual_pc:6.2::mac</vuln:product>
            <vuln:product>cpe:/a:microsoft:virtual_pc:6.0::mac</vuln:product>
            <vuln:product>cpe:/a:microsoft:virtual_pc:6.1::mac</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0115</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:34.647-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9632">9632</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MS</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.microsoft.com/technet/security/bulletin/ms04-005.asp">MS04-005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>ATSTAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.atstake.com/research/advisories/2004/a021004-1.txt">A021004-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15113">virtual-pc-gain-privileges(15113)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3893">3893</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/o-076.shtml">O-076</vuln:reference>
        </vuln:references>
        <vuln:summary>VirtualPC_Services in Microsoft Virtual PC for Mac 6.0 through 6.1 allows local attackers to truncate and overwrite arbitrary files, and execute arbitrary code, via a symlink attack on the VPCServices_Log temporary file.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0127">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.52.3" />
                <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.60" />
                <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.61" />
                <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.61.1" />
                <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.65" />
                <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.65.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpgedview:phpgedview:2.60</vuln:product>
            <vuln:product>cpe:/a:phpgedview:phpgedview:2.61</vuln:product>
            <vuln:product>cpe:/a:phpgedview:phpgedview:2.61.1</vuln:product>
            <vuln:product>cpe:/a:phpgedview:phpgedview:2.65.1</vuln:product>
            <vuln:product>cpe:/a:phpgedview:phpgedview:2.52.3</vuln:product>
            <vuln:product>cpe:/a:phpgedview:phpgedview:2.65</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0127</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:36.633-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9529">9529</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/352355">20040129 PHP Code Injection Vulnerabilities in phpGedView 2.65.1 and prior</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15129">phpgedview-editconfig-directory-traversal(15129)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1008892">1008892</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/displayvuln.php?osvdb_id=3768">3768</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10753/">10753</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via .. (dot dot) sequences in the gedcom_config parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0128">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.52.3" />
                <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.60" />
                <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.61" />
                <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.61.1" />
                <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.65" />
                <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.65.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpgedview:phpgedview:2.60</vuln:product>
            <vuln:product>cpe:/a:phpgedview:phpgedview:2.61</vuln:product>
            <vuln:product>cpe:/a:phpgedview:phpgedview:2.61.1</vuln:product>
            <vuln:product>cpe:/a:phpgedview:phpgedview:2.65.1</vuln:product>
            <vuln:product>cpe:/a:phpgedview:phpgedview:2.52.3</vuln:product>
            <vuln:product>cpe:/a:phpgedview:phpgedview:2.65</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0128</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:36.787-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9531">9531</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/352355">20040129 PHP Code Injection Vulnerabilities in phpGedView 2.65.1 and prior</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14987">phpgedview-gedfilconf-file-include(14987)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3769">3769</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/project/shownotes.php?release_id=141517">http://sourceforge.net/project/shownotes.php?release_id=141517</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10753/">10753</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains a malicious theme.php script.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0129">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.1" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.2.5" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.2.6" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.2_pre1" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.2_rc1" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.2_rc2" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.2_rc3" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.3.2" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.4.0" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.5.0" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.5.4" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.5.5" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.5.5_pl1" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.5.5_rc1" />
                <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.5.5_rc2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.1</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.0</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.0.2</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.2_pre1</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.0.3</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.0.4</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.0.5</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.2_rc1</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.5.5</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.3.2</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.3.1</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.5.4</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.5.1</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.4.0</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.5.2</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.5.0</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.5.5_pl1</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.5.5_rc2</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.2.3</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.2.2</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.5.5_rc1</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.2.6</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.2.5</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.2.4</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.2_rc3</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.2_rc2</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.1.2</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.1.1</vuln:product>
            <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.0.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0129</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:36.960-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9564">9564</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582619125932&amp;w=2">20040203 Arbitrary File Disclosure Vulnerability in phpMyAdmin 2.5.5-pl1 and prior</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.phpmyadmin.net/home_page/relnotes.php?rel=0">http://www.phpmyadmin.net/home_page/relnotes.php?rel=0</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/forum/forum.php?forum_id=350228">http://sourceforge.net/forum/forum.php?forum_id=350228</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200402-05.xml">GLSA-200402-05</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15021">phpmyadmin-dotdot-directory-traversal(15021)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3800">3800</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10769">10769</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0130">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.65" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpgedview:phpgedview:2.65</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0130</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:37.177-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securiteam.com/unixfocus/5NP0M1PBPQ.html">http://www.securiteam.com/unixfocus/5NP0M1PBPQ.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15128">phpgedview-loginphp-path-disclosure(15128)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/6886">6886</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.netvigilance.com/advisory0001">http://www.netvigilance.com/advisory0001</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/alerts/2004/Jan/1008844.html">1008844</vuln:reference>
        </vuln:references>
        <vuln:summary>login.php in phpGedView 2.65 and earlier allows remote attackers to obtain sensitive information via an HTTP request to login.php that does not contain the required username or password parameters, which causes the information to be leaked in an error message.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0131">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:gnu:radius:1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:gnu:radius:1.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0131</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:25:12.853-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/277396">VU#277396</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15046">radius-radprintrequest-dos(15046)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9578">9578</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://ftp.gnu.org/gnu/radius/radius-1.2.tar.gz">http://ftp.gnu.org/gnu/radius/radius-1.2.tar.gz</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3824">3824</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>IDEFENSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/application/poi/display?id=71&amp;type=vulnerabilities&amp;flashstatus=true">20040204 GNU Radius Remote Denial of Service Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10799">10799</vuln:reference>
        </vuln:references>
        <vuln:summary>The rad_print_request function in logger.c for GNU Radius daemon (radiusd) before 1.2 allows remote atackers to cause a denial of service (crash) via a UDP packet with an Acct-Status-Type attribute without a value and no Acct-Session-Id attribute, which causes a null dereference.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0132">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.40" />
                <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.41" />
                <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.42" />
                <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.43" />
                <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.44" />
                <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.45" />
                <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.45b" />
                <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:2.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:2.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:2.0_rc1" />
                <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:2.0_rc2" />
                <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:2.0_rc3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:visualshapers:ezcontents:2.0.2</vuln:product>
            <vuln:product>cpe:/a:visualshapers:ezcontents:2.0.1</vuln:product>
            <vuln:product>cpe:/a:visualshapers:ezcontents:1.42</vuln:product>
            <vuln:product>cpe:/a:visualshapers:ezcontents:1.43</vuln:product>
            <vuln:product>cpe:/a:visualshapers:ezcontents:1.40</vuln:product>
            <vuln:product>cpe:/a:visualshapers:ezcontents:1.41</vuln:product>
            <vuln:product>cpe:/a:visualshapers:ezcontents:2.0_rc3</vuln:product>
            <vuln:product>cpe:/a:visualshapers:ezcontents:2.0_rc2</vuln:product>
            <vuln:product>cpe:/a:visualshapers:ezcontents:1.45b</vuln:product>
            <vuln:product>cpe:/a:visualshapers:ezcontents:1.44</vuln:product>
            <vuln:product>cpe:/a:visualshapers:ezcontents:2.0_rc1</vuln:product>
            <vuln:product>cpe:/a:visualshapers:ezcontents:1.45</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0132</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:25:12.913-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107651585921958&amp;w=2">20040210 PHP Code Injection Vulnerabilities in ezContents 2.0.2 and prior</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15135">ezcontents-multiple-file-include(15135)</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[language_home] parameter to archivednews.php, and a malicious version of lang_admin.php.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0143">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:nokia:6310i" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:nokia:6310i</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0143</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:39.287-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15107">nokia-obex-dos(15107)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9603">9603</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.pentest.co.uk/documents/ptl-2004-01.html">http://www.pentest.co.uk/documents/ptl-2004-01.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634788029065&amp;w=2">20040209 ptl-2004-01: Multiple vulnerabilities in Nokia phones</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0034.html">20040209 ptl-2004-01: Multiple vulnerabilities in Nokia phones</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple vulnerabilities in Nokia 6310(i) Mobile phones allow remote attackers to cause a denial of service (reset) via malformed Bluetooth OBject EXchange (OBEX) messages, probably triggering buffer overflows.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0164">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:kame:racoon:all_versions" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:kame:racoon:all_versions</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0164</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:25:20.557-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:947" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:947" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411758202662&amp;w=2">20040114 Re: unauthorized deletion of IPsec (and ISAKMP) SAs in racoon</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14118">openbsd-isakmp-initialcontact-delete-sa(14118)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14117">openbsd-isakmp-invalidspi-delete-sa(14117)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9417">9417</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>NETBSD</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-001.txt.asc">NetBSD-SA2004-001</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9416">9416</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107403331309838&amp;w=2">20040113 unauthorized deletion of IPsec (and ISAKMP) SAs in racoon</vuln:reference>
        </vuln:references>
        <vuln:summary>KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0096">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.7.9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:mod_python:2.7.9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0096</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:31.383-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.modpython.org/pipermail/mod_python/2004-January/014879.html">[mod_python] 20040122 [ANNOUNCE] Mod_python 2.7.10</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-063.html">RHSA-2004:063</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-058.html">RHSA-2004:058</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200401-03.xml">GLSA-200401-03</vuln:reference>
        </vuln:references>
        <vuln:summary>Unknown vulnerability in mod_python 2.7.9 allows remote attackers to cause a denial of service (httpd crash) via a certain query string, a variant of CAN-2003-0973.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0097">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:openh323_project:pwlib:1.6.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:openh323_project:pwlib:1.6.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0097</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:25:06.930-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:826" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:826" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:803" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:803" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/749342">VU#749342</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-2004-01.html">CA-2004-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-047.html">RHSA-2004:047</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-448">DSA-448</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15202">pwlib-message-dos(15202)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9406">9406</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0099">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:release" />
                <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2.1:release" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:freebsd:freebsd:5.2.1:release</vuln:product>
            <vuln:product>cpe:/o:freebsd:freebsd:5.1:release</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0099</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:31.693-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9533">9533</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FREEBSD</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:01.mksnap_ffs.asc">FreeBSD-SA-04:01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15005">freebsd-mksnapffs-bypass-security(15005)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3790">3790</vuln:reference>
        </vuln:references>
        <vuln:summary>mksnap_ffs in FreeBSD 5.1 and 5.2 only sets the snapshot flag when creating a snapshot for a file system, which causes default values for other flags to be used, possibly disabling security-critical settings and allowing a local user to bypass intended access restrictions.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0103">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:linley_henzell:crawl:4.0.0_b23" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:linley_henzell:crawl:4.0.0_b23</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0103</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:31.837-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-432">DSA-432</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15032">crawl-long-environment-bo(15032)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9566">9566</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10788/">10788</vuln:reference>
        </vuln:references>
        <vuln:summary>crawl before 4.0.0 beta23 does not properly "apply a size check" when copying a certain environment variable, which may allow local users to gain privileges, possibly as a result of a buffer overflow.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0104">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.3" />
                <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.4" />
                <cpe-lang:fact-ref name="cpe:/a:metamail_corporation:metamail:2.7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux_advanced_workstation:2.1::itanium_processor" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:redhat:linux_advanced_workstation:2.1::itanium_processor</vuln:product>
            <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation</vuln:product>
            <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server</vuln:product>
            <vuln:product>cpe:/a:sgi:propack:2.3</vuln:product>
            <vuln:product>cpe:/a:sgi:propack:2.4</vuln:product>
            <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server</vuln:product>
            <vuln:product>cpe:/a:metamail_corporation:metamail:2.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0104</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:25:07.133-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/518518">VU#518518</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9692">9692</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-073.html">RHSA-2004:073</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15259">metamail-printheader-format-string(15259)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15245">metamail-contenttype-format-string(15245)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-449">DSA-449</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10908">10908</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0041.html">20040218 metamail format string bugs and buffer overflows</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734">SSA:2004-049</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:014">MDKSA-2004:014</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/o-083.shtml">O-083</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107713476911429&amp;w=2">20040218 metamail format string bugs and buffer overflows</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0105">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.3" />
                <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.4" />
                <cpe-lang:fact-ref name="cpe:/a:metamail_corporation:metamail:2.7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:linux_advanced_workstation:2.1::itanium_processor" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:redhat:linux_advanced_workstation:2.1::itanium_processor</vuln:product>
            <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation</vuln:product>
            <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server</vuln:product>
            <vuln:product>cpe:/a:sgi:propack:2.3</vuln:product>
            <vuln:product>cpe:/a:sgi:propack:2.4</vuln:product>
            <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server</vuln:product>
            <vuln:product>cpe:/a:metamail_corporation:metamail:2.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0105</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:25:07.210-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/513062">VU#513062</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-073.html">RHSA-2004:073</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15258">metamail-splitmail-subject-bo(15258)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15247">metamail-printheader-nonascii-bo(15247)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-449">DSA-449</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/10908">10908</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0041.html">20040218 metamail format string bugs and buffer overflows</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734">SSA:2004-049</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9692">9692</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:014">MDKSA-2004:014</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/o-083.shtml">O-083</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107713476911429&amp;w=2">20040218 metamail format string bugs and buffer overflows</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0106">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.11" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.12" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1::errata" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.3.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.3" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.0</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.11</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.12</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1::errata</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:3.4</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.3.0</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:3.3</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0106</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:25:07.273-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:832" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:832" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:809" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:809" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053">SSA:2004-043</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-061.html">RHSA-2004:061</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-060.html">RHSA-2004:060</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15206">xfree86-multiple-font-improper-handling(15206)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-059.html">RHSA-2004:059</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2004_06_xf86.html">SuSE-SA:2004:006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-443">DSA-443</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012">MDKSA-2004:012</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2">FLSA:2314</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821">CLA-2004:821</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0082">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0" />
                <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.0" />
                <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:samba:samba:3.0.1</vuln:product>
            <vuln:product>cpe:/a:samba:samba:3.0.0</vuln:product>
            <vuln:product>cpe:/a:samba:samba:3.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0082</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:29.147-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:827" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:827" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9637">9637</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-064.html">RHSA-2004:064</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15132">samba-mksmbpasswd-gain-access(15132)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vuxml.org/freebsd/3388eff9-5d6e-11d8-80e3-0020ed76ef5a.html">http://www.vuxml.org/freebsd/3388eff9-5d6e-11d8-80e3-0020ed76ef5a.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://us1.samba.org/samba/ftp/WHATSNEW-3.0.2a.txt">http://us1.samba.org/samba/ftp/WHATSNEW-3.0.2a.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3919">3919</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/o-078.shtml">O-078</vuln:reference>
        </vuln:references>
        <vuln:summary>The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0083">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.11" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.12" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1::errata" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.3.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.3" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.0</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.11</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.12</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1::errata</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:3.4</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.3.0</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:3.3</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0083</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:25:05.617-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:830" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:830" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:806" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:806" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/820006">VU#820006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9636">9636</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107644835523678&amp;w=2">20040210 iDEFENSESecurityAdvisory02.10.04: XFree86FontInformationFileBufferOverflow</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15130">xfree86-fontalias-bo(15130)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.xfree86.org/cvs/changes">http://www.xfree86.org/cvs/changes</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-061.html">RHSA-2004:061</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-060.html">RHSA-2004:060</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-059.html">RHSA-2004:059</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2004_06_xf86.html">SuSE-SA:2004:006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/application/poi/display?id=72">http://www.idefense.com/application/poi/display?id=72</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-443">DSA-443</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200402-02.xml">GLSA-200402-02</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053">SSA:2004-043</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012">MDKSA-2004:012</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57768-1">57768</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2">FLSA:2314</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107653324115914&amp;w=2">20040211 XFree86 vulnerability exploit</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821">CLA-2004:821</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0084">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.11" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.12" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1::errata" />
                <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.3.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.3" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.0</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.11</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.12</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1::errata</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:3.4</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.3.0</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:3.3</vuln:product>
            <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0084</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:25:05.697-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:831" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:831" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:807" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:807" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/667502">VU#667502</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9652">9652</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-061.html">RHSA-2004:061</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-060.html">RHSA-2004:060</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15200">xfree86-copyisolatin1lLowered-bo(15200)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053">SSA:2004-043</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-059.html">RHSA-2004:059</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2004_06_xf86.html">SuSE-SA:2004:006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/application/poi/display?id=73">http://www.idefense.com/application/poi/display?id=73</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-443">DSA-443</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2">FLSA:2314</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821">CLA-2004:821</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012">MDKSA-2004:012</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57768-1">57768</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107662833512775&amp;w=2">20040212 iDEFENSE Security Advisory 02.11.04: XFree86 Font Information File Buffer Overflow II</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0085">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0085</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:25:05.757-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14992">macosx-mail-undisclosed(14992)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9504">9504</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</vuln:reference>
        </vuln:references>
        <vuln:summary>Unknown vulnerability in the Mail application for Mac OS X 10.1.5 and 10.2.8 with unknown impact, a different vulnerability than CVE-2004-0086.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0086">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0086</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:25:05.837-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9504">9504</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</vuln:reference>
        </vuln:references>
        <vuln:summary>Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0087">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0087</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:25:05.913-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14997">macosx-configd-file-manipulation(14997)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9504">9504</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/6819">6819</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</vuln:reference>
        </vuln:references>
        <vuln:summary>The System Configuration subsystem in Mac OS 10.2.8 and 10.3.2 allows local users to modify network settings, a different vulnerability than CVE-2004-0088.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0088">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0088</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:25:05.977-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9504">9504</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/6820">6820</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</vuln:reference>
        </vuln:references>
        <vuln:summary>The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a different vulnerability than CVE-2004-0087.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0089">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0089</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:25:06.367-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/902374">VU#902374</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9509">9509</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14968">macosx-trublue-environmentvariable-bo(14968)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/6821">6821</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>ATSTAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.atstake.com/research/advisories/2004/a012704-1.txt">A012704-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in TruBlueEnvironment in Mac OS X 10.3.x and 10.2.x allows local users to gain privileges via a long environment variable.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0039">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:checkpoint:firewall-1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0039</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:20.617-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/790771">VU#790771</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA04-036A.html">TA04-036A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14149">fw1-format-string(14149)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9581">9581</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>ISS</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/alerts/id/162">20040204 Checkpoint Firewall-1 HTTP Parsing Format String Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/o-072.shtml">O-072</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.checkpoint.com/techsupport/alerts/security_server.html">http://www.checkpoint.com/techsupport/alerts/security_server.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604682227031&amp;w=2">20040205 Two checkpoint fw-1/vpn-1 vulns</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604682227031&amp;w=2">20040205 Two checkpoint fw-1/vpn-1 vulns</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbitrary code via HTTP requests that cause format string specifiers to be used in an error message, as demonstrated using the scheme of a URI.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0040">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:4.1" />
                <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:4.1:sp1" />
                <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:4.1:sp2" />
                <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:4.1:sp3" />
                <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:4.1:sp4" />
                <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:4.1:sp5" />
                <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:4.1:sp5a" />
                <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:next_generation_fp0" />
                <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:next_generation_fp1" />
                <cpe-lang:fact-ref name="cpe:/a:checkpoint:vpn-1:4.1:sp5a" />
                <cpe-lang:fact-ref name="cpe:/a:checkpoint:vpn-1:next_generation_fp0" />
                <cpe-lang:fact-ref name="cpe:/a:checkpoint:vpn-1:next_generation_fp1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:checkpoint:firewall-1:4.1:sp2</vuln:product>
            <vuln:product>cpe:/a:checkpoint:firewall-1:4.1:sp3</vuln:product>
            <vuln:product>cpe:/a:checkpoint:vpn-1:4.1:sp5a</vuln:product>
            <vuln:product>cpe:/a:checkpoint:firewall-1:4.1:sp1</vuln:product>
            <vuln:product>cpe:/a:checkpoint:firewall-1:next_generation_fp1</vuln:product>
            <vuln:product>cpe:/a:checkpoint:firewall-1:next_generation_fp0</vuln:product>
            <vuln:product>cpe:/a:checkpoint:firewall-1:4.1:sp4</vuln:product>
            <vuln:product>cpe:/a:checkpoint:firewall-1:4.1</vuln:product>
            <vuln:product>cpe:/a:checkpoint:firewall-1:4.1:sp5</vuln:product>
            <vuln:product>cpe:/a:checkpoint:vpn-1:next_generation_fp0</vuln:product>
            <vuln:product>cpe:/a:checkpoint:vpn-1:next_generation_fp1</vuln:product>
            <vuln:product>cpe:/a:checkpoint:firewall-1:4.1:sp5a</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0040</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:24:55.257-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/873334">VU#873334</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9582">9582</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/14150">vpn1-ike-bo(14150)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604682227031&amp;w=2">20040205 Two checkpoint fw-1/vpn-1 vulns</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>ISS</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/alerts/id/163">20040204 Checkpoint VPN-1/SecureClient ISAKMP Buffer Overflow</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/4432">4432</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3821">3821</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/o-073.shtml">O-073</vuln:reference>
        </vuln:references>
        <vuln:summary>Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 4200 allows remote attackers to execute arbitrary code via an ISAKMP packet with a large Certificate Request packet.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0077">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:redhat:bigmem_kernel:2.4.20-8::i686" />
                <cpe-lang:fact-ref name="cpe:/a:redhat:kernel:2.4.20-8::athlon_smp" />
                <cpe-lang:fact-ref name="cpe:/a:redhat:kernel:2.4.20-8::i386" />
                <cpe-lang:fact-ref name="cpe:/a:redhat:kernel:2.4.20-8::i686_smp" />
                <cpe-lang:fact-ref name="cpe:/a:redhat:kernel_doc:2.4.20-8::i386" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:redhat:kernel_source:2.4.20-8::i386_src" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.0" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.1" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.10" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.11" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.12" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.13" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.14" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.15" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.15:pre16" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.15_pre20" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.16" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.16:pre6" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.17" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.18" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.19" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.2" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.20" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.21" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.22" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.23" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.24" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.3" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.4" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.5" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.6" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.7" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.8" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.9" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test1" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test10" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test11" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test12" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test2" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test3" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test4" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test5" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test6" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test7" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test8" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test9" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18::x86" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre1" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre2" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre3" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre4" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre5" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre6" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre7" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre8" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre1" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre2" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre3" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre4" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre5" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre6" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre1" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre4" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre7" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23:pre9" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test1" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test10" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test11" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test2" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test3" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test4" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test5" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test6" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test7" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test8" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test9" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1:rc1" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1:rc2" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2" />
                    <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6_test9_cvs" />
                    <cpe-lang:fact-ref name="cpe:/o:netwosix:netwosix_linux:1.0" />
                    <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:1.5" />
                    <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:2.0" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:redhat:kernel:2.4.20-8::athlon" />
                    <cpe-lang:fact-ref name="cpe:/a:redhat:kernel:2.4.20-8::i386" />
                    <cpe-lang:fact-ref name="cpe:/a:redhat:kernel:2.4.20-8::i686" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.10</vuln:product>
            <vuln:product>cpe:/a:redhat:kernel:2.4.20-8::athlon</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.12</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.11</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.14</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.13</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.16</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.15</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.18</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.17</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.19</vuln:product>
            <vuln:product>cpe:/a:redhat:bigmem_kernel:2.4.20-8::i686</vuln:product>
            <vuln:product>cpe:/a:redhat:kernel_source:2.4.20-8::i386_src</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test10</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test11</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.21</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.20</vuln:product>
            <vuln:product>cpe:/a:redhat:kernel:2.4.20-8::i686</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.24</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.23</vuln:product>
            <vuln:product>cpe:/a:redhat:kernel:2.4.20-8::i686_smp</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.22</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
            <vuln:product>cpe:/o:trustix:secure_linux:1.5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
            <vuln:product>cpe:/a:redhat:kernel:2.4.20-8::i386</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.1:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.1:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18::x86</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.24</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test9</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test8</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.21</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.16:pre6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.22</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.23</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.8</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.9</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.23:pre9</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre8</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.0</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6_test9_cvs</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.15_pre20</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
            <vuln:product>cpe:/o:netwosix:netwosix_linux:1.0</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
            <vuln:product>cpe:/a:redhat:kernel:2.4.20-8::athlon_smp</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.2.15:pre16</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
            <vuln:product>cpe:/o:trustix:secure_linux:2.0</vuln:product>
            <vuln:product>cpe:/a:redhat:kernel_doc:2.4.20-8::i386</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test8</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test9</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test11</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test12</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test10</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0077</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:37:26.397-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:837" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:837" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:825" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:825" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/981222">VU#981222</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9686">9686</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-439">DSA-439</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200403-02.xml">GLSA-200403-02</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15244">linux-mremap-gain-privileges(15244)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107711762014175&amp;w=2">20040218 Second critical mremap() bug found in all Linux kernels</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt">http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734">SSA:2004-049</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-106.html">RHSA-2004:106</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-069.html">RHSA-2004:069</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-066.html">RHSA-2004:066</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-065.html">RHSA-2004:065</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/3986">3986</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html">SuSE-SA:2004:005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-514">DSA-514</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-475">DSA-475</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-470">DSA-470</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-466">DSA-466</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-456">DSA-456</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-454">DSA-454</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-453">DSA-453</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-450">DSA-450</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-444">DSA-444</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-442">DSA-442</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-441">DSA-441</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-440">DSA-440</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2004/dsa-438">DSA-438</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CIAC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ciac.org/ciac/bulletins/o-082.shtml">O-082</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755871932680&amp;w=2">2004-0008</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712137732553&amp;w=2">2004-0007</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:015">MDKSA-2004:015</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://fedoranews.org/updates/FEDORA-2004-079.shtml">FEDORA-2004-079</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000820">CLA-2004:820</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0040.html">20040218 Second critical mremap() bug found in all Linux kernels</vuln:reference>
        </vuln:references>
        <vuln:summary>The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.</vuln:summary>
    </entry>
    <entry id="CVE-2004-0078">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.2.5" />
                <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.2.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.2.5.12" />
                <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.2.5.12_ol" />
                <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.2.5.4" />
                <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.2.5.5" />
                <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.12" />
                <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.12.1" />
                <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.16" />
                <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.17" />
                <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.22" />
                <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.24" />
                <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.25" />
                <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.27" />
                <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.28" />
                <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.4.0" />
                <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.4.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mutt:mutt:1.3.25</vuln:product>
            <vuln:product>cpe:/a:mutt:mutt:1.2.5.12_ol</vuln:product>
            <vuln:product>cpe:/a:mutt:mutt:1.3.16</vuln:product>
            <vuln:product>cpe:/a:mutt:mutt:1.3.24</vuln:product>
            <vuln:product>cpe:/a:mutt:mutt:1.3.27</vuln:product>
            <vuln:product>cpe:/a:mutt:mutt:1.2.5.12</vuln:product>
            <vuln:product>cpe:/a:mutt:mutt:1.4.0</vuln:product>
            <vuln:product>cpe:/a:mutt:mutt:1.3.28</vuln:product>
            <vuln:product>cpe:/a:mutt:mutt:1.3.17</vuln:product>
            <vuln:product>cpe:/a:mutt:mutt:1.4.1</vuln:product>
            <vuln:product>cpe:/a:mutt:mutt:1.2.5.4</vuln:product>
            <vuln:product>cpe:/a:mutt:mutt:1.2.5.5</vuln:product>
            <vuln:product>cpe:/a:mutt:mutt:1.3.12</vuln:product>
            <vuln:product>cpe:/a:mutt:mutt:1.3.22</vuln:product>
            <vuln:product>cpe:/a:mutt:mutt:1.2.5</vuln:product>
            <vuln:product>cpe:/a:mutt:mutt:1.3.12.1</vuln:product>
            <vuln:product>cpe:/a:mutt:mutt:1.2.5.1</vuln:product>
            <vuln:product>cpe:/a:mutt:mutt:1.2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2004-0078</vuln:cve-id>
        <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:25:02.210-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:838" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:838" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:811" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:811" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/9641">9641</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-051.html">RHSA-2004:051</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2004-050.html">RHSA-2004:050</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/15134">mut