<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/0.1" xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" xmlns:patch="http://scap.nist.gov/schema/patch/0.1" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" nvd_xml_version="2.0" pub_date="2013-06-18T07:55:25" xsi:schemaLocation="http://scap.nist.gov/schema/patch/0.1 http://nvd.nist.gov/schema/patch_0.1.xsd http://scap.nist.gov/schema/scap-core/0.1 http://nvd.nist.gov/schema/scap-core_0.1.xsd http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
  <entry id="CVE-2004-0001">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0001</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:16.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:868" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:868" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/337238" xml:lang="en">VU#337238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-017.html" xml:lang="en">RHSA-2004:017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14888" xml:lang="en">linux-ptrace-gain-privilege(14888)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9429" xml:lang="en">9429</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200402-06.xml" xml:lang="en">GLSA-200402-06</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:868" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:868" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10910" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10910" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0002">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.0:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.5.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.5.1:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.5:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.0:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1.1:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.2:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:release_p38"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4:release_p42"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:release_p32"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:release_p20"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:release_p17"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8:pre-release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8:release_p6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.9:pre-release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0:release_p14"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:release_p5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.5.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.9:pre-release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.5:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.5.1:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:release_p17</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:release_p38</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1.1:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4:release_p42</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.0:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1.1:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.9</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.0:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:release_p32</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.2:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0:release_p14</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1:release_p5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:release_p20</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0:alpha</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8:pre-release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.5.1:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8:release_p6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.0:alpha</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0002</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:24:44.507-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.freebsd.org/pipermail/cvs-src/2004-January/016271.html" xml:lang="en">http://lists.freebsd.org/pipermail/cvs-src/2004-January/016271.html</vuln:reference>
    </vuln:references>
    <vuln:summary>The TCP MSS (maximum segment size) functionality in netinet allows remote attackers to cause a denial of service (resource exhaustion) via (1) a low MTU, which causes a large number of small packets to be produced, or (2) via a large number of packets with a small TCP payload, which cause a large number of calls to the resource-intensive sowakeup function.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0003">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.22</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0003</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:25.753-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9204" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9204" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:834" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:834" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1017" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1017" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-044.html" xml:lang="en">RHSA-2004:044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.linuxcompatible.org/print25630.html" xml:lang="en">http://www.linuxcompatible.org/print25630.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-065.html" xml:lang="en">RHSA-2004:065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html" xml:lang="en">SuSE-SA:2004:005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-495" xml:lang="en">DSA-495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-491" xml:lang="en">DSA-491</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-489" xml:lang="en">DSA-489</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-482" xml:lang="en">DSA-482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-481" xml:lang="en">DSA-481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-480" xml:lang="en">DSA-480</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-479" xml:lang="en">DSA-479</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15029" xml:lang="en">linux-r128-gain-priviliges(15029)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/2004/TLSA-2004-14.txt" xml:lang="en">TLSA-2004-14</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9570" xml:lang="en">9570</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-166.html" xml:lang="en">RHSA-2004:166</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-106.html" xml:lang="en">RHSA-2004:106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:029" xml:lang="en">MDKSA-2004:029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-145.shtml" xml:lang="en">O-145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-127.shtml" xml:lang="en">O-127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-126.shtml" xml:lang="en">O-126</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-121.shtml" xml:lang="en">O-121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-082.shtml" xml:lang="en">O-082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/12075" xml:lang="en">12075</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11891" xml:lang="en">11891</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11464" xml:lang="en">11464</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11376" xml:lang="en">11376</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11370" xml:lang="en">11370</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11369" xml:lang="en">11369</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11362" xml:lang="en">11362</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11361" xml:lang="en">11361</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11202" xml:lang="en">11202</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10912" xml:lang="en">10912</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10911" xml:lang="en">10911</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10782" xml:lang="en">10782</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:834" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:834" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1017" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1017" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9204" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9204" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."</vuln:summary>
  </entry>
  <entry id="CVE-2004-0004">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openca:openca:0.9.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openca:openca:0.9.1.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0004</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:16.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/336446" xml:lang="en">VU#336446</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9435" xml:lang="en">9435</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openca.org/news/CAN-2004-0004.txt" xml:lang="en">http://www.openca.org/news/CAN-2004-0004.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14847" xml:lang="en">openca-improper-signature-verification(14847)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3615" xml:lang="en">3615</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107427313700554&amp;w=2" xml:lang="en">20040116 [OpenCA Advisory] Vulnerability in signature verification</vuln:reference>
    </vuln:references>
    <vuln:summary>The libCheckSignature function in crypto-utils.lib for OpenCA 0.9.1.6 and earlier only compares the serial of the signer's certificate and the one in the database, which can cause OpenCA to incorrectly accept a signature if the certificate's chain is trusted by OpenCA's chain directory, allowing remote attackers to spoof requests from other users.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0005">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rob_flynn:gaim:0.75"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2004-0005</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:16.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/655974" xml:lang="en">VU#655974</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/404470" xml:lang="en">VU#404470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/226974" xml:lang="en">VU#226974</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/190366" xml:lang="en">VU#190366</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-434" xml:lang="en">DSA-434</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security.e-matters.de/advisories/012004.html" xml:lang="en">http://security.e-matters.de/advisories/012004.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2" xml:lang="en">20040126 Advisory 01/2004: 12 x Gaim remote overflows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14944" xml:lang="en">gaim-mime-decoder-oob(14944)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14942" xml:lang="en">gaim-mime-decoder-bo(14942)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14938" xml:lang="en">gaim-sscanf-oob(14938)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14935" xml:lang="en">gaim-yahoodecode-offbyone-bo(14935)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.361158" xml:lang="en">SSA:2004-026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008850" xml:lang="en">1008850</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3736" xml:lang="en">3736</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2004_04_gaim.html" xml:lang="en">SuSE-SA:2004:004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/content/view/105690/104/" xml:lang="en">GLSA-200401-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813" xml:lang="en">CLA-2004:813</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html" xml:lang="en">20040126 Advisory 01/2004: 12 x Gaim remote overflows</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal encoding in yahoo_decode that causes a null byte to be written beyond the buffer, (2) octal encoding in yahoo_decode that causes a pointer to reference memory beyond the terminating null byte, (3) a quoted printable string to the gaim_quotedp_decode MIME decoder that causes a null byte to be written beyond the buffer, and (4) quoted printable encoding in gaim_quotedp_decode that causes a pointer to reference memory beyond the terminating null byte.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0006">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rob_flynn:gaim:0.75"/>
        <cpe-lang:fact-ref name="cpe:/a:ultramagnetic:ultramagnetic:0.81"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ultramagnetic:ultramagnetic:0.81</vuln:product>
      <vuln:product>cpe:/a:rob_flynn:gaim:0.75</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0006</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:26.330-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10222" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10222" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:818" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:818" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/871838" xml:lang="en">VU#871838</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/527142" xml:lang="en">VU#527142</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/503030" xml:lang="en">VU#503030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/444158" xml:lang="en">VU#444158</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/371382" xml:lang="en">VU#371382</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/297198" xml:lang="en">VU#297198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-032.html" xml:lang="en">RHSA-2004:032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://ultramagnetic.sourceforge.net/advisories/001.html" xml:lang="en">http://ultramagnetic.sourceforge.net/advisories/001.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security.e-matters.de/advisories/012004.html" xml:lang="en">http://security.e-matters.de/advisories/012004.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-045.html" xml:lang="en">RHSA-2004:045</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-033.html" xml:lang="en">RHSA-2004:033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2004_04_gaim.html" xml:lang="en">SuSE-SA:2004:004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-434" xml:lang="en">DSA-434</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200401-04.xml" xml:lang="en">GLSA-200401-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2" xml:lang="en">20040126 Advisory 01/2004: 12 x Gaim remote overflows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc" xml:lang="en">20040201-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14947" xml:lang="en">gaim-http-proxy-bo(14947)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14945" xml:lang="en">gaim-urlparser-bo(14945)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14943" xml:lang="en">gaim-yahoopacketread-keyname-bo(14943)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14941" xml:lang="en">gaim-login-value-bo(14941)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14940" xml:lang="en">gaim-login-name-bo(14940)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14939" xml:lang="en">gaim-yahoowebpending-cookie-bo(14939)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.361158" xml:lang="en">SSA:2004-026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008850" xml:lang="en">1008850</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9489" xml:lang="en">9489</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3732" xml:lang="en">3732</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3731" xml:lang="en">3731</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:006" xml:lang="en">MDKSA-2004:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522432613022&amp;w=2" xml:lang="en">20040127 Ultramagnetic Advisory #001:  Multiple vulnerabilities in Gaim code</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813" xml:lang="en">CLA-2004:813</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html" xml:lang="en">20040126 Advisory 01/2004: 12 x Gaim remote overflows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" xml:lang="en">20040202-01-U</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10222" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10222" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:818" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:818" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0007">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rob_flynn:gaim:0.74"/>
        <cpe-lang:fact-ref name="cpe:/a:ultramagnetic:ultramagnetic:0.81"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ultramagnetic:ultramagnetic:0.81</vuln:product>
      <vuln:product>cpe:/a:rob_flynn:gaim:0.74</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0007</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:26.457-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9906" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9906" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:819" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:819" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/197142" xml:lang="en">VU#197142</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-033.html" xml:lang="en">RHSA-2004:033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-434" xml:lang="en">DSA-434</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://ultramagnetic.sourceforge.net/advisories/001.html" xml:lang="en">http://ultramagnetic.sourceforge.net/advisories/001.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security.e-matters.de/advisories/012004.html" xml:lang="en">http://security.e-matters.de/advisories/012004.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522432613022&amp;w=2" xml:lang="en">20040127 Ultramagnetic Advisory #001:  Multiple vulnerabilities in Gaim code</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-032.html" xml:lang="en">RHSA-2004:032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200401-04.xml" xml:lang="en">GLSA-200401-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14946" xml:lang="en">gaim-extractinfo-bo(14946)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.361158" xml:lang="en">SSA:2004-026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008850" xml:lang="en">1008850</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9489" xml:lang="en">9489</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/6281" xml:lang="en">SuSE-SA:2004:004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3733" xml:lang="en">3733</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:006" xml:lang="en">MDKSA-2004:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2" xml:lang="en">20040126 Advisory 01/2004: 12 x Gaim remote overflows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813" xml:lang="en">CLA-2004:813</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html" xml:lang="en">20040126 Advisory 01/2004: 12 x Gaim remote overflows</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:819" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:819" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9906" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9906" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0008">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rob_flynn:gaim:0.74"/>
        <cpe-lang:fact-ref name="cpe:/a:ultramagnetic:ultramagnetic:0.81"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ultramagnetic:ultramagnetic:0.81</vuln:product>
      <vuln:product>cpe:/a:rob_flynn:gaim:0.74</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0008</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:26.580-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9469" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9469" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:820" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:820" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/779614" xml:lang="en">VU#779614</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-032.html" xml:lang="en">RHSA-2004:032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://ultramagnetic.sourceforge.net/advisories/001.html" xml:lang="en">http://ultramagnetic.sourceforge.net/advisories/001.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security.e-matters.de/advisories/012004.html" xml:lang="en">http://security.e-matters.de/advisories/012004.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522432613022&amp;w=2" xml:lang="en">20040127 Ultramagnetic Advisory #001:  Multiple vulnerabilities in Gaim code</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-045.html" xml:lang="en">RHSA-2004:045</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-033.html" xml:lang="en">RHSA-2004:033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-434" xml:lang="en">DSA-434</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200401-04.xml" xml:lang="en">GLSA-200401-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc" xml:lang="en">20040201-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14937" xml:lang="en">gaim-directim-bo(14937)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008850" xml:lang="en">1008850</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3734" xml:lang="en">3734</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:006" xml:lang="en">MDKSA-2004:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522338611564&amp;w=2" xml:lang="en">20040127 [slackware-security]  GAIM security update (SSA:2004-026-01)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2" xml:lang="en">20040126 Advisory 01/2004: 12 x Gaim remote overflows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813" xml:lang="en">CLA-2004:813</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html" xml:lang="en">20040126 Advisory 01/2004: 12 x Gaim remote overflows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" xml:lang="en">20040202-01-U</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:820" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:820" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9469" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9469" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0009">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache-ssl:apache-ssl:1.3.28_1.52"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache-ssl:apache-ssl:1.3.28_1.52</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0009</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:17.600-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107619127531765&amp;w=2" xml:lang="en">20040206 Apache-SSL security advisory - apache_1.3.28+ssl_1.52 and prior</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15065" xml:lang="en">apachessl-default-password(15065)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9590" xml:lang="en">9590</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.apache-ssl.org/advisory-20040206.txt" xml:lang="en">http://www.apache-ssl.org/advisory-20040206.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3877" xml:lang="en">3877</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016870.html" xml:lang="en">20040206 [apache-ssl] Apache-SSL security advisory - apache_1.3.28+ssl_1.52 and prior</vuln:reference>
    </vuln:references>
    <vuln:summary>Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0010">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23:pre9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23:pre9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18::x86</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0010</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:26.800-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11388" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11388" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:835" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:835" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1035" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1035" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9691" xml:lang="en">9691</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-069.html" xml:lang="en">RHSA-2004:069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-479" xml:lang="en">DSA-479</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15250" xml:lang="en">linux-ncplookup-gain-privileges(15250)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-188.html" xml:lang="en">RHSA-2004:188</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-065.html" xml:lang="en">RHSA-2004:065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html" xml:lang="en">SuSE-SA:2004:005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-495" xml:lang="en">DSA-495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-491" xml:lang="en">DSA-491</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-489" xml:lang="en">DSA-489</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-482" xml:lang="en">DSA-482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-481" xml:lang="en">DSA-481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-480" xml:lang="en">DSA-480</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/advisories/6759" xml:lang="en">TLSA-2004-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:015" xml:lang="en">MDKSA-2004:015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-082.shtml" xml:lang="en">O-082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/updates/FEDORA-2004-079.shtml" xml:lang="en">FEDORA-2004-079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000820" xml:lang="en">CLA-2004:820</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:835" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:835" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1035" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1035" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11388" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11388" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0011">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:debian:fsp:2.81.b18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:debian:fsp:2.81.b18</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0011</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:18.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9377" xml:lang="en">9377</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-416" xml:lang="en">DSA-416</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14155" xml:lang="en">fsp-boundry-error-bo(14155)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-048.shtml" xml:lang="en">O-048</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in fsp before 2.81.b18 allows remote users to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0013">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:jabber_software_foundation:jabber_server:1.4.2a"/>
        <cpe-lang:fact-ref name="cpe:/a:jabber_software_foundation:jabber_server:1.4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jabber_software_foundation:jabber_server:1.4.3</vuln:product>
      <vuln:product>cpe:/a:jabber_software_foundation:jabber_server:1.4.2a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0013</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:18.180-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:005" xml:lang="en">MDKSA-2004:005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-414" xml:lang="en">DSA-414</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14158" xml:lang="en">jabber-ssl-connections-dos(14158)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9376" xml:lang="en">9376</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3345" xml:lang="en">3345</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10559" xml:lang="en">10559</vuln:reference>
    </vuln:references>
    <vuln:summary>jabber 1.4.2, 1.4.2a, and possibly earlier versions, does not properly handle SSL connections, which allows remote attackers to cause a denial of service (crash).</vuln:summary>
  </entry>
  <entry id="CVE-2004-0014">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:nd:nd:0.8.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nd:nd:0.8.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0014</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:24:50.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9365" xml:lang="en">9365</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-412" xml:lang="en">DSA-412</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14141" xml:lang="en">nd-long-string-bo(14141)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008616" xml:lang="en">1008616</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10550" xml:lang="en">10550</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10549" xml:lang="en">10549</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in the nd WebDAV interface 0.8.2 and earlier allows remote web servers to execute arbitrary code via certain long strings.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0015">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:vbox3:vbox3:0.1.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vbox3:vbox3:0.1.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0015</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:18.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-418" xml:lang="en">DSA-418</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9381" xml:lang="en">9381</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14170" xml:lang="en">vbox3-gain-privileges(14170)</vuln:reference>
    </vuln:references>
    <vuln:summary>vbox3 0.1.8 and earlier does not properly drop privileges before executing a user-provided TCL script, which allows local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0016">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpgroupware:phpgroupware:0.9.14"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpgroupware:phpgroupware:0.9.14</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0016</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:18.633-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-419" xml:lang="en">DSA-419</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9387" xml:lang="en">9387</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/13489" xml:lang="en">phpgroupware-calendar-file-include(13489)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6860" xml:lang="en">6860</vuln:reference>
    </vuln:references>
    <vuln:summary>The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers to create and execute PHP files.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0017">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpgroupware:phpgroupware:0.9.14"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpgroupware:phpgroupware:0.9.14</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0017</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:18.773-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-419" xml:lang="en">DSA-419</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9386" xml:lang="en">9386</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008662" xml:lang="en">1008662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10591" xml:lang="en">10591</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform unauthorized database operations.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0028">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:samba:jitterbug:1.6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:samba:jitterbug:1.6.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0028</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:18.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-420" xml:lang="en">DSA-420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9397" xml:lang="en">9397</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14207" xml:lang="en">jitterbug-execute-code(14207)</vuln:reference>
    </vuln:references>
    <vuln:summary>jitterbug 1.6.2 does not properly sanitize inputs, which allows remote authenticated users to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0029">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0029</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:19.133-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14153" xml:lang="en">lotus-notes-insecure-permissions(14153)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9366" xml:lang="en">9366</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008623" xml:lang="en">1008623</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3424" xml:lang="en">3424</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.excluded.org/advisories/advisory05.txt" xml:lang="en">http://www.excluded.org/advisories/advisory05.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10566" xml:lang="en">10566</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340897710308&amp;w=2" xml:lang="en">20040106 Lotus Notes Domino 6.0.2 (linux) faulty default permissions</vuln:reference>
    </vuln:references>
    <vuln:summary>Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0030">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.61"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpgedview:phpgedview:2.61</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0030</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:19.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14159" xml:lang="en">phpgedview-pgvbasedirectory-file-include(14159)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9368" xml:lang="en">9368</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3343" xml:lang="en">3343</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10565" xml:lang="en">10565</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2" xml:lang="en">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008632" xml:lang="en">1008632</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0031">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.61"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpgedview:phpgedview:2.61</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0031</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:19.430-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2" xml:lang="en">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14161" xml:lang="en">phpgedview-modify-admin-password(14161)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3403" xml:lang="en">3403</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10565" xml:lang="en">10565</vuln:reference>
    </vuln:references>
    <vuln:summary>PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTTP request to editconfig.php.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0032">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.61"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpgedview:phpgedview:2.61</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0032</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:19.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2" xml:lang="en">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14160" xml:lang="en">phpgedview-search-xss(14160)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9369" xml:lang="en">9369</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3402" xml:lang="en">3402</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10565" xml:lang="en">10565</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script via the firstname parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0033">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.61"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpgedview:phpgedview:2.61</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0033</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:19.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2" xml:lang="en">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14162" xml:lang="en">phpgedview-admin-info-disclosure(14162)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9371" xml:lang="en">9371</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3404" xml:lang="en">3404</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10565" xml:lang="en">10565</vuln:reference>
    </vuln:references>
    <vuln:summary>admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0034">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:3.4.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phorum:phorum:3.4.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0034</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:19.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14145" xml:lang="en">phorum-common-xss(14145)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9361" xml:lang="en">9361</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10567" xml:lang="en">10567</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://phorum.org/" xml:lang="en">http://phorum.org/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340481804110&amp;w=2" xml:lang="en">20040105 Multiple Vulnerabilities in Phorum 3.4.5</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008633" xml:lang="en">1008633</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3510" xml:lang="en">3510</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3506" xml:lang="en">3506</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3434" xml:lang="en">3434</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.4.5 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the phorum_check_xss function in common.php, (2) the EditError variable in profile.php, and (3) the Error variable in login.php.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0035">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:3.4.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phorum:phorum:3.4.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0035</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:20.023-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14146" xml:lang="en">phorum-register-sql-injection(14146)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9363" xml:lang="en">9363</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340481804110&amp;w=2" xml:lang="en">20040105 Multiple Vulnerabilities in Phorum 3.4.5</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3508" xml:lang="en">3508</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10567" xml:lang="en">10567</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in register.php for Phorum 3.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the hide_email parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0036">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:2.3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jelsoft:vbulletin:2.3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0036</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:20.163-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340358202123&amp;w=2" xml:lang="en">20040105 vBulletin Forum 2.3.xx calendar.php SQL Injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14144" xml:lang="en">vbulletin-calendar-sql-injection(14144)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vbulletin.com/forum/showthread.php?postid=588825" xml:lang="en">http://www.vbulletin.com/forum/showthread.php?postid=588825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9360" xml:lang="en">9360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3344" xml:lang="en">3344</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in calendar.php for vBulletin Forum 2.3.x before 2.3.4 allows remote attackers to steal sensitive information via the eventid parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0037">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:opentext:opentext_firstclass_desktop_client:7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:opentext:opentext_firstclass_desktop_client:7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0037</vuln:cve-id>
    <vuln:published-datetime>2004-01-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:20.303-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14151" xml:lang="en">firstclassclient-execute-code(14151)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9370" xml:lang="en">9370</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3442" xml:lang="en">3442</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10556" xml:lang="en">10556</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340950611167&amp;w=2" xml:lang="en">20040105 FirstClass Client 7.1: Command Execution via Email Web Link</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008609" xml:lang="en">1008609</vuln:reference>
    </vuln:references>
    <vuln:summary>FirstClass Desktop Client 7.1 allows remote attackers to execute arbitrary commands via hyperlinks in FirstClass RTF messages.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0038">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:3.0:sp2a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:3.0</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5.1</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5:sp1</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:3.0:sp2a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0038</vuln:cve-id>
    <vuln:published-datetime>2004-06-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:20.460-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14166" xml:lang="en">epolicy-execute-commands(14166)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/alerts/id/173" xml:lang="en">20040510 McAfee ePolicy Orchestrator Remote Compromise Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10200" xml:lang="en">10200</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.osvdb.org/5626" xml:lang="en">http://www.osvdb.org/5626</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://download.nai.com/products/patches/ePO/v2.x/Patch14.txt" xml:lang="en">http://download.nai.com/products/patches/ePO/v2.x/Patch14.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3 allows remote attackers to execute arbitrary commands via certain HTTP POST requests to the spipe/file handler on ePO TCP port 81.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0039">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:checkpoint:firewall-1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0039</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:15:01.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/790771" xml:lang="en">VU#790771</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-036A.html" xml:lang="en">TA04-036A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14149" xml:lang="en">fw1-format-string(14149)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9581" xml:lang="en">9581</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/alerts/id/162" xml:lang="en">20040204 Checkpoint Firewall-1 HTTP Parsing Format String Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-072.shtml" xml:lang="en">O-072</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.checkpoint.com/techsupport/alerts/security_server.html" xml:lang="en">http://www.checkpoint.com/techsupport/alerts/security_server.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604682227031&amp;w=2" xml:lang="en">20040205 Two checkpoint fw-1/vpn-1 vulns</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbitrary code via HTTP requests that cause format string specifiers to be used in an error message, as demonstrated using the scheme of a URI.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0040">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:4.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:4.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:4.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:4.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:4.1:sp5"/>
        <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:4.1:sp5a"/>
        <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:next_generation_fp0"/>
        <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:next_generation_fp1"/>
        <cpe-lang:fact-ref name="cpe:/a:checkpoint:vpn-1:4.1:sp5a"/>
        <cpe-lang:fact-ref name="cpe:/a:checkpoint:vpn-1:next_generation_fp0"/>
        <cpe-lang:fact-ref name="cpe:/a:checkpoint:vpn-1:next_generation_fp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:checkpoint:firewall-1:4.1:sp5a</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:4.1:sp1</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:4.1</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:4.1:sp5</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:4.1:sp2</vuln:product>
      <vuln:product>cpe:/a:checkpoint:vpn-1:next_generation_fp0</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:4.1:sp4</vuln:product>
      <vuln:product>cpe:/a:checkpoint:vpn-1:next_generation_fp1</vuln:product>
      <vuln:product>cpe:/a:checkpoint:vpn-1:4.1:sp5a</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:next_generation_fp1</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:next_generation_fp0</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:4.1:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0040</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:24:55.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/873334" xml:lang="en">VU#873334</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9582" xml:lang="en">9582</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14150" xml:lang="en">vpn1-ike-bo(14150)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604682227031&amp;w=2" xml:lang="en">20040205 Two checkpoint fw-1/vpn-1 vulns</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/alerts/id/163" xml:lang="en">20040204 Checkpoint VPN-1/SecureClient ISAKMP Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/4432" xml:lang="en">4432</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3821" xml:lang="en">3821</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-073.shtml" xml:lang="en">O-073</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 4200 allows remote attackers to execute arbitrary code via an ISAKMP packet with a large Certificate Request packet.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0041">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mod_auth_shadow:mod_auth_shadow:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_auth_shadow:mod_auth_shadow:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_auth_shadow:mod_auth_shadow:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_auth_shadow:mod_auth_shadow:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_auth_shadow:mod_auth_shadow:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mod_auth_shadow:mod_auth_shadow:1.2</vuln:product>
      <vuln:product>cpe:/a:mod_auth_shadow:mod_auth_shadow:1.3</vuln:product>
      <vuln:product>cpe:/a:mod_auth_shadow:mod_auth_shadow:1.4</vuln:product>
      <vuln:product>cpe:/a:mod_auth_shadow:mod_auth_shadow:1.1</vuln:product>
      <vuln:product>cpe:/a:mod_auth_shadow:mod_auth_shadow:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0041</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:20.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-421" xml:lang="en">DSA-421</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008675" xml:lang="en">1008675</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9404" xml:lang="en">9404</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3454" xml:lang="en">3454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10612" xml:lang="en">10612</vuln:reference>
    </vuln:references>
    <vuln:summary>The mod_auth_shadow module 1.4 and earlier does not properly enforce the expiration of a user account and password, which could allow remote authenticated users to bypass intended access restrictions.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0042">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:beasts:vsftpd:1.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:beasts:vsftpd:1.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0042</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:24:55.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008628" xml:lang="en">1008628</vuln:reference>
    </vuln:references>
    <vuln:summary>vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0043">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.6.0.1351"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:yahoo:messenger:5.6.0.1351</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0043</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:21.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9383" xml:lang="en">9383</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2004-January/015334.html" xml:lang="en">20040108 Yahoo Instant Messenger Long Filename Downloading Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14171" xml:lang="en">yahoo-messenger-filename-bo(14171)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008651" xml:lang="en">1008651</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3437" xml:lang="en">3437</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10573" xml:lang="en">10573</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107357996802255&amp;w=2" xml:lang="en">20040108 Yahoo Instant Messenger Long Filename Downloading Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in the download feature.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0044">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cisco:personal_assistant:1.4%281%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:personal_assistant:1.4%282%29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:personal_assistant:1.4%281%29</vuln:product>
      <vuln:product>cpe:/a:cisco:personal_assistant:1.4%282%29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0044</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:21.397-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20040108-pa.shtml" xml:lang="en">20040108 Cisco Personal Assistant User Password Bypass Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14172" xml:lang="en">ciscopersonalassistant-config-file-access(14172)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9384" xml:lang="en">9384</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3430" xml:lang="en">3430</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco Personal Assistant 1.4(1) and 1.4(2) disables password authentication when "Allow Only Cisco CallManager Users" is enabled and the Corporate Directory settings refer to the directory service being used by Cisco CallManager, which allows remote attackers to gain access with a valid username.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0045">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:isc:inn:2.4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:isc:inn:2.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0045</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:21.553-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/759020" xml:lang="en">VU#759020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9382" xml:lang="en">9382</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2004-01/0064.html" xml:lang="en">20040108 [OpenPKG-SA-2004.001] OpenPKG Security Advisory (inn)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2004-01/0063.html" xml:lang="en">20040107 [SECURITY] INN: Buffer overflow in control message handling</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14190" xml:lang="en">inn-artpost-control-message-bo(14190)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.365791" xml:lang="en">SSA:2004-014-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10578" xml:lang="en">10578</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the ARTpost function in art.c in the control message handling code for INN 2.4.0 may allow remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0046">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:snapstream:snapstream_pvs:lite"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2004-0046</vuln:cve-id>
    <vuln:published-datetime>2004-02-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:21.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14164" xml:lang="en">snapstream-quotation-xss(14164)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9375" xml:lang="en">9375</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3440" xml:lang="en">3440</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008646" xml:lang="en">1008646</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10575" xml:lang="en">10575</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107350313917867&amp;w=2" xml:lang="en">20040106 SnapStream PVS LITE Cross Site Scripting Vulnerabillity</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script or HTML via a GET request containing a terminating '"' (double quote) character.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0047">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:yamamoto_hirotaka:trr19:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:yamamoto_hirotaka:trr19:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0047</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:21.850-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-430" xml:lang="en">DSA-430</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14975" xml:lang="en">trr19-gain-privileges(14975)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9520" xml:lang="en">9520</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10744/" xml:lang="en">10744</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008875" xml:lang="en">1008875</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3747" xml:lang="en">3747</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10745" xml:lang="en">10745</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple programs in trr19 1.0 do not properly drop privileges before executing a system command, which could allow local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0049">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:helix_universal_mobile_server:10.1.1.120"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:helix_universal_server:9.0.2.881"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:realnetworks:helix_universal_mobile_server:10.1.1.120</vuln:product>
      <vuln:product>cpe:/a:realnetworks:helix_universal_server:9.0.2.881</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0049</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:21.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication approximated="true">SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://service.real.com/help/faq/security/040112_dos/" xml:lang="en">http://service.real.com/help/faq/security/040112_dos/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9421" xml:lang="en">9421</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://service.real.com/help/faq/security/security022604.html" xml:lang="en">http://service.real.com/help/faq/security/security022604.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/357834" xml:lang="en">20040318 ptl-2004-02: RealNetworks Helix Server 9 Administration Server Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://seclists.org/lists/vulnwatch/2004/Jan-Mar/0057.html" xml:lang="en">20040318 ptl-2004-02: RealNetworks Helix Server 9 Administration Server Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:summary>Helix Universal Server/Proxy 9 and Mobile Server 10 allow remote attackers to cause a denial of service via certain HTTP POST messages to the Administration System port.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0050">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:verity:ultraseek:5.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:verity:ultraseek:5.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0050</vuln:cve-id>
    <vuln:published-datetime>2004-06-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:24:56.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/16066" xml:lang="en">ultraseek-error-path-disclosure(16066)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108377388114888&amp;w=2" xml:lang="en">20040505 Corsaire Security Advisory - Verity Ultraseek path disclosure issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020952.html" xml:lang="en">20040505 Corsaire Security Advisory - Verity Ultraseek path disclosure issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2004-q2/0024.html" xml:lang="en">20040505 Corsaire Security Advisory - Verity Ultraseek path disclosure issue</vuln:reference>
    </vuln:references>
    <vuln:summary>Verity Ultraseek before 5.2.2 allows remote attackers to obtain the full pathname of the document root via an MS-DOS device name in the web search option, such as (1) NUL, (2) CON, (3) AUX, (4) COM1, (5) COM2, and others.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0051">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.31"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.32"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.2</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.3</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.10</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.8</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.31</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.32</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.6</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.2</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.14</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.0</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.5</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.1</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.7</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.3</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.11</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.3</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.15</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.7</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.0</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.13</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.4</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0051</vuln:cve-id>
    <vuln:published-datetime>2004-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:24:56.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/17337" xml:lang="en">mime-contenttransfer-filter-bypass(17337)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" xml:lang="en">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109517788100063&amp;w=2" xml:lang="en">20040914 Corsaire Security Advisory - Multiple vendor MIME Content-Transfer-Encoding mechanism issue</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard but frequently supported Content-Transfer-Encoding values such as (1) uuencode, (2) mac-binhex40, and (3) yenc, which may be interpreted differently by mail clients.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0052">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.31"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.32"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.2</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.3</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.10</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.8</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.31</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.32</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.6</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.2</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.14</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.0</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.5</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.1</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.7</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.3</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.11</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.3</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.15</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.7</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.0</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.13</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.4</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0052</vuln:cve-id>
    <vuln:published-datetime>2004-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:24:57.133-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/17334" xml:lang="en">mime-separator-filtering-bypass(17334)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" xml:lang="en">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109517669115891&amp;w=2" xml:lang="en">20040914 Corsaire Security Advisory - Multiple vendor MIME separator issue</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard separator characters, or use standard separators incorrectly, within MIME headers, fields, parameters, or values, which may be interpreted differently by mail clients.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0053">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.31"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.32"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.2</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.3</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.10</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.8</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.31</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.32</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.6</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.2</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.14</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.0</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.5</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.1</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.7</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.3</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.11</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.3</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.15</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.7</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.0</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.13</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.4</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0053</vuln:cve-id>
    <vuln:published-datetime>2004-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:24:57.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/17331" xml:lang="en">mime-rfc2047-filtering-bypass(17331)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" xml:lang="en">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109520704408739&amp;w=2" xml:lang="en">20040914 Corsaire Security Advisory - Multiple vendor MIME RFC2047 encoding issue</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use fields that use RFC2047 encoding, which may be interpreted differently by mail clients.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0054">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1e"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2t"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:12.1t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1e</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2t</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0054</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-03-04T00:21:09.437-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4884" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4884" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/749342" xml:lang="en">VU#749342</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2004-01.html" xml:lang="en">CA-2004-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20040113-h323.shtml" xml:lang="en">20040113 Vulnerabilities in H.323 Message Processing</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uniras.gov.uk/vuls/2004/006489/h323.htm" xml:lang="en">http://www.uniras.gov.uk/vuls/2004/006489/h323.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008685" xml:lang="en">1008685</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9406" xml:lang="en">9406</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4884" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4884" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0055">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lbl:tcpdump:3.7</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.6.2</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.5.2</vuln:product>
      <vuln:product>cpe:/a:lbl:tcpdump:3.7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0055</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:29.987-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9989" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9989" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:853" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:853" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:850" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:850" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/955526" xml:lang="en">VU#955526</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7090" xml:lang="en">7090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-008.html" xml:lang="en">RHSA-2004:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00015.html" xml:lang="en">[fedora-announce-list] 20040311 Re: [SECURITY] Fedora Core 1 Update: tcpdump-3.7.2-8.fc1.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00009.html" xml:lang="en">FEDORA-2004-092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00006.html" xml:lang="en">FEDORA-2004-090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-425" xml:lang="en">DSA-425</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/12179/" xml:lang="en">12179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11032/" xml:lang="en">11032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11022" xml:lang="en">11022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10718" xml:lang="en">10718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10652" xml:lang="en">10652</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10644" xml:lang="en">10644</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10639" xml:lang="en">10639</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10636" xml:lang="en">10636</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://lwn.net/Alerts/66445/" xml:lang="en">2004-0004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" xml:lang="en">APPLE-SA-2004-02-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc" xml:lang="en">20040103-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.9/SCOSA-2004.9.txt" xml:lang="en">SCOSA-2004.9</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2004-008.0.txt" xml:lang="en">CSSA-2004-008.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008735" xml:lang="en">1008735</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html" xml:lang="en">FLSA:1222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:008" xml:lang="en">MDKSA-2004:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=tcpdump-workers&amp;m=107325073018070&amp;w=2" xml:lang="en">[tcpdump-workers] multiple vulnerabilities in tcpdump 3.8.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577418225627&amp;w=2" xml:lang="en">20040131 [FLSA-2004:1222] Updated tcpdump resolves security vulnerabilites (resend with correct paths)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000832" xml:lang="en">CLSA-2003:832</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" xml:lang="en">20040202-01-U</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:850" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:850" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:853" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:853" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9989" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9989" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0056">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:nortel:business_communications_manager"/>
        <cpe-lang:fact-ref name="cpe:/h:nortel:802.11_wireless_ip_gateway"/>
        <cpe-lang:fact-ref name="cpe:/h:nortel:succession_communication_server_1000"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:nortel:802.11_wireless_ip_gateway</vuln:product>
      <vuln:product>cpe:/h:nortel:succession_communication_server_1000</vuln:product>
      <vuln:product>cpe:/a:nortel:business_communications_manager</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0056</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:23.210-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/749342" xml:lang="en">VU#749342</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2004-01.html" xml:lang="en">CA-2004-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uniras.gov.uk/vuls/2004/006489/h323.htm" xml:lang="en">http://www.uniras.gov.uk/vuls/2004/006489/h323.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008687" xml:lang="en">1008687</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9406" xml:lang="en">9406</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple vulnerabilities in the H.323 protocol implementation for Nortel Networks Business Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, and 802.11 Wireless IP Gateway allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0057">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.8.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lbl:tcpdump:3.8.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0057</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:30.207-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11197" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11197" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:854" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:854" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:851" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:851" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/174086" xml:lang="en">VU#174086</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9423" xml:lang="en">9423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-007.html" xml:lang="en">RHSA-2004:007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-425" xml:lang="en">DSA-425</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14837" xml:lang="en">tcpdump-rawprint-isakmp-dos(14837)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/350238/30/21640/threaded" xml:lang="en">20040119 [ESA-20040119-002] 'tcpdump' multiple vulnerabilities.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-008.html" xml:lang="en">RHSA-2004:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00015.html" xml:lang="en">[fedora-announce-list] 20040311 Re: [SECURITY] Fedora Core 1 Update: tcpdump-3.7.2-8.fc1.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00009.html" xml:lang="en">FEDORA-2004-092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00006.html" xml:lang="en">FEDORA-2004-090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/12179/" xml:lang="en">12179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11032/" xml:lang="en">11032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11022" xml:lang="en">11022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10718" xml:lang="en">10718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10668" xml:lang="en">10668</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10652" xml:lang="en">10652</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10644" xml:lang="en">10644</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10639" xml:lang="en">10639</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10636" xml:lang="en">10636</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=tcpdump-workers&amp;m=107325073018070&amp;w=2" xml:lang="en">[tcpdump-workers] multiple vulnerabilities in tcpdump 3.8.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://lwn.net/Alerts/66805/" xml:lang="en">ESA-20040119-002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://lwn.net/Alerts/66445/" xml:lang="en">2004-0004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" xml:lang="en">APPLE-SA-2004-02-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc" xml:lang="en">20040103-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.9/SCOSA-2004.9.txt" xml:lang="en">SCOSA-2004.9</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2004-008.0.txt" xml:lang="en">CSSA-2004-008.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008716" xml:lang="en">1008716</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html" xml:lang="en">FLSA:1222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:008" xml:lang="en">MDKSA-2004:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577418225627&amp;w=2" xml:lang="en">20040131 [FLSA-2004:1222] Updated tcpdump resolves security vulnerabilites (resend with correct paths)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" xml:lang="en">20040202-01-U</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11197" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11197" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:851" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:851" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:854" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:854" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0058">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.9.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.9.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0058</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:23.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14214" xml:lang="en">antivir-tmpfile-insecure(14214)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008702" xml:lang="en">1008702</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3496" xml:lang="en">3496</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10620" xml:lang="en">10620</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107402026023763&amp;w=2" xml:lang="en">20040113 symlink vul for Antivir / Linux Version 2.0.9-9 (maybe lower)</vuln:reference>
    </vuln:references>
    <vuln:summary>Antivir / Linux 2.0.9-9, and possibly earlier versions, allows local users to overwrite arbitrary files via a symlink attack on the .pid_antivir_$$ temporary file.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0059">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:lionmax_software:www_file_share_pro:2.42"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lionmax_software:www_file_share_pro:2.42</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0059</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:23.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008779" xml:lang="en">1008779</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2" xml:lang="en">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0060">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:lionmax_software:www_file_share_pro:2.42"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lionmax_software:www_file_share_pro:2.42</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0060</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:23.803-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008779" xml:lang="en">1008779</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2" xml:lang="en">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</vuln:reference>
    </vuln:references>
    <vuln:summary>WWW File Share Pro 2.42 and earlier allows remote attackers to cause a denial of service (crash) via a large POST request.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0061">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:lionmax_software:www_file_share_pro:2.42"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lionmax_software:www_file_share_pro:2.42</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0061</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:23.960-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008779" xml:lang="en">1008779</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2" xml:lang="en">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</vuln:reference>
    </vuln:references>
    <vuln:summary>WWW File Share Pro 2.42 and earlier allows remote attackers to bypass directory access restrictions via (1) a URL with a trailing . (dot), or (2) a URI with a leading slash or backslash character.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0062">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:fishnet:fishcart:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fishnet:fishcart:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0062</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:24:59.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411850203994&amp;w=2" xml:lang="en">20040114 FishCart Integer Overflow / Rounding Error</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008731" xml:lang="en">1008731</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the rnd arithmetic rounding function for various versions of FishCart before 3.1 allows remote attackers to "cause negative totals" via an order with a large quantity.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0063">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ncipher:payshield_spp_library:1.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:ncipher:payshield_spp_library:1.5.18"/>
        <cpe-lang:fact-ref name="cpe:/a:ncipher:payshield_spp_library:1.6.18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ncipher:payshield_spp_library:1.3.12</vuln:product>
      <vuln:product>cpe:/a:ncipher:payshield_spp_library:1.6.18</vuln:product>
      <vuln:product>cpe:/a:ncipher:payshield_spp_library:1.5.18</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0063</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:24.290-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ncipher.com/support/advisories/advisory8_payshield.html" xml:lang="en">http://www.ncipher.com/support/advisories/advisory8_payshield.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14832" xml:lang="en">payshield-incorrect-request-verification(14832)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9422" xml:lang="en">9422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3537" xml:lang="en">3537</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411819503569&amp;w=2" xml:lang="en">20040114 nCipher Advisory #8: payShield library may verify bad requests</vuln:reference>
    </vuln:references>
    <vuln:summary>The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g. by accepting an invalid PIN number.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0064">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:suse:suse_linux:9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0064</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:24.430-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9411" xml:lang="en">9411</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008703" xml:lang="en">1008703</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3460" xml:lang="en">3460</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10623" xml:lang="en">10623</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107402658600437&amp;w=2" xml:lang="en">20040113 SuSE linux 9.0 YaST config Skribt [exploit]</vuln:reference>
    </vuln:references>
    <vuln:summary>The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0065">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.65"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpgedview:phpgedview:2.65</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0065</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:24.587-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2" xml:lang="en">20040112 More phpGedView Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11925" xml:lang="en">11925</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11910" xml:lang="en">11910</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2) placelist.php.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0066">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.65"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpgedview:phpgedview:2.65</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0066</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:24.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2" xml:lang="en">20040112 More phpGedView Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14215" xml:lang="en">phpgedview-path-disclosure(14215)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3464" xml:lang="en">3464</vuln:reference>
    </vuln:references>
    <vuln:summary>phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0067">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.65"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpgedview:phpgedview:2.65</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0067</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-13T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2" xml:lang="en">20040112 More phpGedView Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/36285" xml:lang="en">phpgedview-login-xss(36285)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14212" xml:lang="en">phpgedview-multiple-xss(14212)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2995" xml:lang="en">ADV-2007-2995</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11907" xml:lang="en">11907</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11906" xml:lang="en">11906</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11905" xml:lang="en">11905</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11904" xml:lang="en">11904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11903" xml:lang="en">11903</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11894" xml:lang="en">11894</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11891" xml:lang="en">11891</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11890" xml:lang="en">11890</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11888" xml:lang="en">11888</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11882" xml:lang="en">11882</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11880" xml:lang="en">11880</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11868" xml:lang="en">11868</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/477881/100/0/threaded" xml:lang="en">20070827 PhpGedView login page multiple XSS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3479" xml:lang="en">3479</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3478" xml:lang="en">3478</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3477" xml:lang="en">3477</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3476" xml:lang="en">3476</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3475" xml:lang="en">3475</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3474" xml:lang="en">3474</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3473" xml:lang="en">3473</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1018613" xml:lang="en">1018613</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/26628" xml:lang="en">26628</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php.  NOTE: some aspects of vector 10 were later reported to affect 4.1.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0068">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpdig.net:phpdig:1.6.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpdig.net:phpdig:1.6.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0068</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:25.023-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9424" xml:lang="en">9424</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.phpdig.net/showthread.php?s=58bcc71c822830ec3bbdaae6d56846e0&amp;threadid=393" xml:lang="en">http://www.phpdig.net/showthread.php?s=58bcc71c822830ec3bbdaae6d56846e0&amp;threadid=393</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107412194008671&amp;w=2" xml:lang="en">20040114 PhpDig 1.6.x: remote command execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14826" xml:lang="en">phpdig-config-file-include(14826)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in config.php for PhpDig 1.6.5 and earlier allows remote attackers to execute arbitrary PHP code by modifying the $relative_script_path parameter to reference a URL on a remote web server that contains the code.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0069">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hd_soft:windows_ftp_server:1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hd_soft:windows_ftp_server:1.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0069</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:25.180-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9385" xml:lang="en">9385</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107401398014761&amp;w=2" xml:lang="en">20040113 exploit for HD Soft Windows FTP Server 1.6</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107367110805273&amp;w=2" xml:lang="en">20040108 Windows FTP Server Format String Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008658" xml:lang="en">1008658</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0070">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:visualshapers:ezcontents</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0070</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:25.337-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14199" xml:lang="en">ezcontents-php-file-include(14199)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9396" xml:lang="en">9396</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6878" xml:lang="en">6878</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ezcontents.org/forum/viewtopic.php?t=361" xml:lang="en">http://www.ezcontents.org/forum/viewtopic.php?t=361</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392588915627&amp;w=2" xml:lang="en">20040110 Remote Code Execution in ezContents</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the link parameter to reference a URL on a remote web server that contains the code.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0071">
    <vuln:cve-id>CVE-2004-0071</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14203" xml:lang="en">manpagelookup-directory-traversal(14203)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9395" xml:lang="en">9395</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392764118403&amp;w=2" xml:lang="en">20040110 PHP Manpage lookup directory transversal / file disclosing</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008689" xml:lang="en">1008689</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0072">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:accipiter:accipiter_direct_server:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:accipiter:accipiter_direct_server:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0072</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:25.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9389" xml:lang="en">9389</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14198" xml:lang="en">accipterdirectserver-directory-traversal(14198)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392576215418&amp;w=2" xml:lang="en">20040109 Directory Traversal in Accipiter Direct Server 6.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0274.html" xml:lang="en">20040109 Directory Traversal in Accipiter Direct Server 6.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3433" xml:lang="en">3433</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10600" xml:lang="en">10600</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via encoded \.. (backslash .., "%5c%2e%2e") sequences in an HTTP request.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0073">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:stoitsov:easydynamicpages:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:stoitsov:easydynamicpages:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0073</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:25.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9338" xml:lang="en">9338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14136" xml:lang="en">easydynamicpages-php-file-include(14136)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3408" xml:lang="en">3408</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3318" xml:lang="en">3318</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008584" xml:lang="en">1008584</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10535" xml:lang="en">10535</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107307457327707&amp;w=2" xml:lang="en">20040102 include() vuln in EasyDynamicPages v.2.0</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to execute arbitrary PHP code by modifying the edp_relative_path parameter to reference a URL on a remote web server that contains a malicious serverdata.php script.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0074">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:michael_bischoff:xsok:1.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:michael_bischoff:xsok:1.02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0074</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:25.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9341" xml:lang="en">9341</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14910" xml:lang="en">xsok-lang-bo(14910)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14906" xml:lang="en">xsok-long-xsokdir-bo(14906)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9352" xml:lang="en">9352</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107332542918529&amp;w=2" xml:lang="en">20040103 xsok local games exploit (2)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107307407027259&amp;w=2" xml:lang="en">20040102 xsok local games exploit</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, or (2) a long -xsokdir command line argument, a different vulnerability than CVE-2003-0949.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0075">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23:pre9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23_ow2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24_ow1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.24_ow1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23:pre9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18::x86</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23_ow2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0075</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:26.023-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:836" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:836" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9690" xml:lang="en">9690</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-065.html" xml:lang="en">RHSA-2004:065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15246" xml:lang="en">linux-vicam-dos(15246)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-293.html" xml:lang="en">RHSA-2005:293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html" xml:lang="en">SuSE-SA:2004:005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-082.shtml" xml:lang="en">O-082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:015" xml:lang="en">MDKSA-2004:015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846" xml:lang="en">CLA-2004:846</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:836" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:836" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9948" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9948" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0076">
    <vuln:cve-id>CVE-2004-0076</vuln:cve-id>
    <vuln:published-datetime>2004-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:02.070-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was removed from consideration by its Candidate Numbering Authority.  Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0077">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:redhat:bigmem_kernel:2.4.20-8::i686"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kernel:2.4.20-8::athlon_smp"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kernel:2.4.20-8::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kernel:2.4.20-8::i686_smp"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:kernel_doc:2.4.20-8::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:redhat:kernel_source:2.4.20-8::i386_src"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.0"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.1"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.10"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.11"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.13"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.14"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.15"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.15:pre16"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.15_pre20"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.16"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.16:pre6"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.17"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.18"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.19"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.2"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.20"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.21"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.22"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.23"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.24"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.3"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.4"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.5"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.6"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.7"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.8"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.9"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test1"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test10"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test11"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test12"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test2"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test3"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test4"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test5"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test6"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test7"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test8"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test9"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18::x86"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre1"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre2"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre3"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre4"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre5"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre6"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre7"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre8"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre1"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre2"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre3"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre4"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre5"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre6"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre1"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre4"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre7"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23:pre9"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test1"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test10"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test11"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test2"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test3"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test4"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test5"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test6"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test7"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test8"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test9"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1:rc1"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1:rc2"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6_test9_cvs"/>
          <cpe-lang:fact-ref name="cpe:/o:netwosix:netwosix_linux:1.0"/>
          <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:1.5"/>
          <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:2.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:redhat:kernel:2.4.20-8::athlon"/>
          <cpe-lang:fact-ref name="cpe:/a:redhat:kernel:2.4.20-8::i386"/>
          <cpe-lang:fact-ref name="cpe:/a:redhat:kernel:2.4.20-8::i686"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:trustix:secure_linux:1.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23:pre9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test11</vuln:product>
      <vuln:product>cpe:/a:redhat:kernel_doc:2.4.20-8::i386</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test6</vuln:product>
      <vuln:product>cpe:/o:trustix:secure_linux:2.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.23</vuln:product>
      <vuln:product>cpe:/a:redhat:kernel_source:2.4.20-8::i386_src</vuln:product>
      <vuln:product>cpe:/a:redhat:kernel:2.4.20-8::athlon</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.16:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre1</vuln:product>
      <vuln:product>cpe:/a:redhat:kernel:2.4.20-8::athlon_smp</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre5</vuln:product>
      <vuln:product>cpe:/a:redhat:kernel:2.4.20-8::i686_smp</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre2</vuln:product>
      <vuln:product>cpe:/a:redhat:kernel:2.4.20-8::i686</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18::x86</vuln:product>
      <vuln:product>cpe:/o:netwosix:netwosix_linux:1.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test9</vuln:product>
      <vuln:product>cpe:/a:redhat:kernel:2.4.20-8::i386</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6_test9_cvs</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.15:pre16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.15_pre20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
      <vuln:product>cpe:/a:redhat:bigmem_kernel:2.4.20-8::i686</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0077</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:26.397-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:837" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:837" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:825" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:825" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/981222" xml:lang="en">VU#981222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9686" xml:lang="en">9686</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-439" xml:lang="en">DSA-439</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200403-02.xml" xml:lang="en">GLSA-200403-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15244" xml:lang="en">linux-mremap-gain-privileges(15244)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107711762014175&amp;w=2" xml:lang="en">20040218 Second critical mremap() bug found in all Linux kernels</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt" xml:lang="en">http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734" xml:lang="en">SSA:2004-049</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-106.html" xml:lang="en">RHSA-2004:106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-069.html" xml:lang="en">RHSA-2004:069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-066.html" xml:lang="en">RHSA-2004:066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-065.html" xml:lang="en">RHSA-2004:065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3986" xml:lang="en">3986</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html" xml:lang="en">SuSE-SA:2004:005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-514" xml:lang="en">DSA-514</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-475" xml:lang="en">DSA-475</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-470" xml:lang="en">DSA-470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-466" xml:lang="en">DSA-466</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-456" xml:lang="en">DSA-456</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-454" xml:lang="en">DSA-454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-453" xml:lang="en">DSA-453</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-450" xml:lang="en">DSA-450</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-444" xml:lang="en">DSA-444</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-442" xml:lang="en">DSA-442</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-441" xml:lang="en">DSA-441</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-440" xml:lang="en">DSA-440</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-438" xml:lang="en">DSA-438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-082.shtml" xml:lang="en">O-082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755871932680&amp;w=2" xml:lang="en">2004-0008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712137732553&amp;w=2" xml:lang="en">2004-0007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:015" xml:lang="en">MDKSA-2004:015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/updates/FEDORA-2004-079.shtml" xml:lang="en">FEDORA-2004-079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000820" xml:lang="en">CLA-2004:820</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0040.html" xml:lang="en">20040218 Second critical mremap() bug found in all Linux kernels</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:825" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:825" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:837" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:837" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11137" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11137" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0078">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.2.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.2.5.12_ol"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.2.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.2.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.12.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.22"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.24"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.25"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.27"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.3.28"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mutt:mutt:1.3.12</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.2.5</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.16</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.12.1</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.28</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.2.5.12</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.27</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.2.5.5</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.24</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.25</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.17</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.2.1</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.2.5.1</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.2.5.4</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.3.22</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.4.0</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.4.1</vuln:product>
      <vuln:product>cpe:/a:mutt:mutt:1.2.5.12_ol</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0078</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:02.210-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:838" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:838" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:811" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:811" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9641" xml:lang="en">9641</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-051.html" xml:lang="en">RHSA-2004:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-050.html" xml:lang="en">RHSA-2004:050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15134" xml:lang="en">mutt-index-menu-bo(15134)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/126336" xml:lang="en">http://bugs.debian.org/126336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053" xml:lang="en">SSA:2004-043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3918" xml:lang="en">3918</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:010" xml:lang="en">MDKSA-2004:010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107884956930903&amp;w=2" xml:lang="en">20040309 [OpenPKG-SA-2004.005] OpenPKG Security Advisory (mutt)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696262905039&amp;w=2" xml:lang="en">20040215 LNSA-#2004-0001: mutt remote crash</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107651677817933&amp;w=2" xml:lang="en">20040211 Mutt-1.4.2 fixes buffer overflow.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-013.0.txt" xml:lang="en">CSSA-2004-013.0</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10648" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10648" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:838" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:838" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:811" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:811" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0079">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:1.1_%283.005%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:2.1_%280.208%29"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:aaa_server"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:apache-based_web_server:2.0.43.00"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:apache-based_web_server:2.0.43.04"/>
        <cpe-lang:fact-ref name="cpe:/h:symantec:clientless_vpn_gateway_4400:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cisco:ciscoworks_common_management_foundation:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:ciscoworks_common_services:2.2"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:converged_communications_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg200:4.31.29"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg200:4.4"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg203:4.31.29"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg203:4.4"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg208"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg208:4.4"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg5:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg5:4.3"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg5:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.23"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:8.05"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::workstation_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.3"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2811%29e"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2811b%29e"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2811b%29e12"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2811b%29e14"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2813%29e9"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2819%29e1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%2814%29sy"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%2814%29sy1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sy"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2za"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.2.2"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.2.3"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.2.4"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:intuity_audix:::lx"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:intuity_audix:5.1.46"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:intuity_audix:s3210"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:intuity_audix:s3400"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:100_r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:10000_r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:2000_r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:5"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:500"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:5000_r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:5x"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:7500_r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:::vsx-ng-ai"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:2.0::gx"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:next_generation_fp0"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:next_generation_fp1"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:next_generation_fp2"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:provider-1:4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:provider-1:4.1:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:provider-1:4.1:sp2"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:provider-1:4.1:sp3"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:provider-1:4.1:sp4"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:vpn-1:next_generation_fp0"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:vpn-1:next_generation_fp1"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:vpn-1:next_generation_fp2"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:vpn-1:vsx_ng_with_application_intelligence"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:access_registrar"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:application_and_content_networking_software"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:css_secure_content_accelerator:1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:css_secure_content_accelerator:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:css11000_content_services_switch"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:okena_stormwatch:3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:pix_firewall:6.2.2_.111"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:threat_response"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:6.10"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:6.10_b4"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:7.1_0.1.02"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:7.1_0.2.06"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:7.10"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:7.10_.0.06s"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:7.2_0.0.03"/>
          <cpe-lang:fact-ref name="cpe:/a:hp:wbem:a.01.05.08"/>
          <cpe-lang:fact-ref name="cpe:/a:hp:wbem:a.02.00.00"/>
          <cpe-lang:fact-ref name="cpe:/a:hp:wbem:a.02.00.01"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.2.2"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.2_rc1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.2_rc2"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.3"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.3_rc1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.3_rc2"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.3_rc3"/>
          <cpe-lang:fact-ref name="cpe:/a:neoteris:instant_virtual_extranet:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:neoteris:instant_virtual_extranet:3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:neoteris:instant_virtual_extranet:3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:neoteris:instant_virtual_extranet:3.3"/>
          <cpe-lang:fact-ref name="cpe:/a:neoteris:instant_virtual_extranet:3.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.5"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.5.12a"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.5.27"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.7"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.7.1:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:imanager:1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:imanager:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6c"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6d"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6e"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6f"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6g"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6h"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6i"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6j"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6k"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta1"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta2"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta3"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7a"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7b"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7c"/>
          <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.6-15::i386"/>
          <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.6b-3::i386"/>
          <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.7a-2::i386"/>
          <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.7a-2::i386_dev"/>
          <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.7a-2::i386_perl"/>
          <cpe-lang:fact-ref name="cpe:/a:rsa:bsafe_ssl-j_sdk:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:rsa:bsafe_ssl-j_sdk:3.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:rsa:bsafe_ssl-j_sdk:3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.3"/>
          <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.4"/>
          <cpe-lang:fact-ref name="cpe:/a:sgi:propack:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:servercluster:2.5"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:servercluster:2.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_fullcluster:1_2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_fullcluster:1_3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_fullcluster:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_fullcluster:2.5"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_fullcluster:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_securitycluster:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_securitycluster:2.5"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_webcluster:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_webcluster:2.5"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.5.17"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.5.18"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.7"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.2"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.2.4"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate_vpn_client:1.7"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate_vpn_client:1.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate_vpn_client:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate_vpn_client:2.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate_vpn_client:2.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate_vpn_client:2.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:tarantella:tarantella_enterprise:3.20"/>
          <cpe-lang:fact-ref name="cpe:/a:tarantella:tarantella_enterprise:3.30"/>
          <cpe-lang:fact-ref name="cpe:/a:tarantella:tarantella_enterprise:3.40"/>
          <cpe-lang:fact-ref name="cpe:/a:vmware:gsx_server:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:vmware:gsx_server:2.0.1_build_2129"/>
          <cpe-lang:fact-ref name="cpe:/a:vmware:gsx_server:2.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:vmware:gsx_server:2.5.1_build_5336"/>
          <cpe-lang:fact-ref name="cpe:/a:vmware:gsx_server:3.0_build_7592"/>
          <cpe-lang:fact-ref name="cpe:/h:avaya:s8300:r2.0.0"/>
          <cpe-lang:fact-ref name="cpe:/h:avaya:s8300:r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/h:avaya:s8500:r2.0.0"/>
          <cpe-lang:fact-ref name="cpe:/h:avaya:s8500:r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/h:avaya:s8700:r2.0.0"/>
          <cpe-lang:fact-ref name="cpe:/h:avaya:s8700:r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/h:bluecoat:proxysg"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:content_services_switch_11500"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:gss_4480_global_site_selector"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:gss_4490_global_site_selector"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:mds_9000"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:secure_content_accelerator:10000"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2.0.01"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2.0.02"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2.0.03"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2.0.04"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2.1"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2.1.02"/>
          <cpe-lang:fact-ref name="cpe:/h:sun:crypto_accelerator_4000:1.0"/>
          <cpe-lang:fact-ref name="cpe:/o:bluecoat:cacheos_ca_sa:4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/o:bluecoat:cacheos_ca_sa:4.1.12"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.0"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.0%281%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.0%282%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.0%283%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.0%284%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.0%284.101%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.1%281%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.1%282%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.1%283%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.1%284%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.1%285%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.2"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.2%281%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.2%282%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.2%283%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.2%283.100%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.3"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.3%281%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.3%282%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.3%283.102%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.3%283.109%29"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta1</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:7.2_0.0.03</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::workstation_server</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.3%283.102%29</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2.1.02</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_fullcluster:1_3.0</vuln:product>
      <vuln:product>cpe:/a:vmware:gsx_server:2.0.1_build_2129</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2.0.04</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.1%282%29</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.5</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate_vpn_client:1.7</vuln:product>
      <vuln:product>cpe:/a:stonesoft:servercluster:2.5</vuln:product>
      <vuln:product>cpe:/h:symantec:clientless_vpn_gateway_4400:5.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:8.0</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.2%283.100%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.1%284%29</vuln:product>
      <vuln:product>cpe:/h:cisco:mds_9000</vuln:product>
      <vuln:product>cpe:/a:cisco:application_and_content_networking_software</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.0</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.7</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_webcluster:2.0</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2.1</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.2%281%29</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.2</vuln:product>
      <vuln:product>cpe:/a:vmware:gsx_server:2.5.1</vuln:product>
      <vuln:product>cpe:/h:avaya:sg200:4.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.9</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.3.1</vuln:product>
      <vuln:product>cpe:/h:hp:aaa_server</vuln:product>
      <vuln:product>cpe:/a:cisco:pix_firewall:6.2.2_.111</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate_vpn_client:2.0.7</vuln:product>
      <vuln:product>cpe:/a:rsa:bsafe_ssl-j_sdk:3.0</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module:1.1.3</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:2.0</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.0%283%29</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.5.18</vuln:product>
      <vuln:product>cpe:/h:bluecoat:proxysg</vuln:product>
      <vuln:product>cpe:/a:checkpoint:provider-1:4.1:sp1</vuln:product>
      <vuln:product>cpe:/a:neoteris:instant_virtual_extranet:3.0</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.2.1</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.6</vuln:product>
      <vuln:product>cpe:/h:avaya:sg5:4.4</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:8.05</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.7a-2::i386_dev</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.5.12a</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:7.10_.0.06s</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6f</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1:releng</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6c</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.3</vuln:product>
      <vuln:product>cpe:/a:avaya:intuity_audix:::lx</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.23</vuln:product>
      <vuln:product>cpe:/a:neoteris:instant_virtual_extranet:3.3.1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7a</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.2.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.2</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.3_rc2</vuln:product>
      <vuln:product>cpe:/a:hp:wbem:a.01.05.08</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.3_rc3</vuln:product>
      <vuln:product>cpe:/a:stonesoft:servercluster:2.5.2</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:100_r2.0.1</vuln:product>
      <vuln:product>cpe:/a:hp:wbem:a.02.00.01</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:1.5</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:3.0</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.6.3</vuln:product>
      <vuln:product>cpe:/h:avaya:sg5:4.3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%2814%29sy</vuln:product>
      <vuln:product>cpe:/a:rsa:bsafe_ssl-j_sdk:3.0.1</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:5</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_fullcluster:2.0</vuln:product>
      <vuln:product>cpe:/a:tarantella:tarantella_enterprise:3.20</vuln:product>
      <vuln:product>cpe:/a:checkpoint:vpn-1:next_generation_fp1</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.1.1</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module:2.1_%280.208%29</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.0.3</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.7.1</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_fullcluster:2.5</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.0.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1:release</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:5000_r2.0.1</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_fullcluster:3.0</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.3</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.1</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:2000_r2.0.1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2811b%29e</vuln:product>
      <vuln:product>cpe:/h:avaya:sg200:4.31.29</vuln:product>
      <vuln:product>cpe:/h:avaya:s8500:r2.0.1</vuln:product>
      <vuln:product>cpe:/a:cisco:css11000_content_services_switch</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2.0.02</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:next_generation_fp2</vuln:product>
      <vuln:product>cpe:/o:bluecoat:cacheos_ca_sa:4.1.12</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:4.0</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.5</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.1%283%29</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.3_rc1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2819%29e1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6d</vuln:product>
      <vuln:product>cpe:/a:checkpoint:provider-1:4.1:sp3</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.3</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.0%281%29</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.7.1:sp1</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate_vpn_client:2.0</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate_vpn_client:2.0.9</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.2.3</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6g</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:7500_r2.0.1</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:6.10_b4</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7c</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.2.2</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:7.1_0.2.06</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.0%284%29</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.3</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:7.1_0.1.02</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6k</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/a:avaya:intuity_audix:5.1.46</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.0%282%29</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.2.4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%2814%29sy1</vuln:product>
      <vuln:product>cpe:/h:hp:apache-based_web_server:2.0.43.04</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_fullcluster:1_2.0</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.9</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.2.4</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.7</vuln:product>
      <vuln:product>cpe:/a:vmware:gsx_server:2.0</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta3</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.2%283%29</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.1</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2</vuln:product>
      <vuln:product>cpe:/a:checkpoint:vpn-1:vsx_ng_with_application_intelligence</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:5x</vuln:product>
      <vuln:product>cpe:/a:rsa:bsafe_ssl-j_sdk:3.1</vuln:product>
      <vuln:product>cpe:/a:checkpoint:provider-1:4.1:sp4</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:10000_r2.0.1</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.2</vuln:product>
      <vuln:product>cpe:/a:cisco:ciscoworks_common_management_foundation:2.1</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_securitycluster:2.0</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.4</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.1%281%29</vuln:product>
      <vuln:product>cpe:/a:cisco:css_secure_content_accelerator:1.0</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.2.2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6e</vuln:product>
      <vuln:product>cpe:/o:bluecoat:cacheos_ca_sa:4.1.10</vuln:product>
      <vuln:product>cpe:/a:neoteris:instant_virtual_extranet:3.1</vuln:product>
      <vuln:product>cpe:/a:cisco:threat_response</vuln:product>
      <vuln:product>cpe:/h:cisco:call_manager</vuln:product>
      <vuln:product>cpe:/a:checkpoint:vpn-1:next_generation_fp2</vuln:product>
      <vuln:product>cpe:/a:tarantella:tarantella_enterprise:3.30</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.3</vuln:product>
      <vuln:product>cpe:/a:checkpoint:vpn-1:next_generation_fp0</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.2</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:next_generation_fp1</vuln:product>
      <vuln:product>cpe:/a:cisco:access_registrar</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::advanced_server</vuln:product>
      <vuln:product>cpe:/h:sun:crypto_accelerator_4000:1.0</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.3%282%29</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_webcluster:2.5</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.3</vuln:product>
      <vuln:product>cpe:/h:avaya:sg203:4.31.29</vuln:product>
      <vuln:product>cpe:/h:hp:apache-based_web_server:2.0.43.00</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.3</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.2_rc1</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.1%285%29</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2.0.03</vuln:product>
      <vuln:product>cpe:/h:avaya:s8300:r2.0.0</vuln:product>
      <vuln:product>cpe:/a:hp:wbem:a.02.00.00</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.6b-3::i386</vuln:product>
      <vuln:product>cpe:/a:neoteris:instant_virtual_extranet:3.3</vuln:product>
      <vuln:product>cpe:/h:avaya:converged_communications_server:2.0</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.7</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2811b%29e12</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.6.2</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.6.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.3%283.109%29</vuln:product>
      <vuln:product>cpe:/h:avaya:s8700:r2.0.1</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.3%281%29</vuln:product>
      <vuln:product>cpe:/a:cisco:okena_stormwatch:3.2</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module:1.1_%283.005%29</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8:releng</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2813%29e9</vuln:product>
      <vuln:product>cpe:/h:avaya:s8700:r2.0.0</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.3</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:next_generation_fp0</vuln:product>
      <vuln:product>cpe:/h:avaya:s8300:r2.0.1</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.2.1:release</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:3.0</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.7.2</vuln:product>
      <vuln:product>cpe:/a:avaya:intuity_audix:s3400</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6h</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7</vuln:product>
      <vuln:product>cpe:/a:avaya:intuity_audix:s3210</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2za</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate_vpn_client:2.0.8</vuln:product>
      <vuln:product>cpe:/h:cisco:gss_4480_global_site_selector</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:6.10</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.3.1</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.7a-2::i386</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.2%282%29</vuln:product>
      <vuln:product>cpe:/a:checkpoint:provider-1:4.1:sp2</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module:1.1.2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6i</vuln:product>
      <vuln:product>cpe:/h:avaya:sg5:4.2</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.1</vuln:product>
      <vuln:product>cpe:/h:cisco:gss_4490_global_site_selector</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.6</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2811b%29e14</vuln:product>
      <vuln:product>cpe:/h:avaya:sg208</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2811%29e</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7b</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.5.17</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.7a-2::i386_perl</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.0%284.101%29</vuln:product>
      <vuln:product>cpe:/h:cisco:secure_content_accelerator:10000</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.2.1</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.0</vuln:product>
      <vuln:product>cpe:/h:cisco:content_services_switch_11500</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.4</vuln:product>
      <vuln:product>cpe:/a:tarantella:tarantella_enterprise:3.40</vuln:product>
      <vuln:product>cpe:/h:avaya:sg203:4.4</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.4</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.0.1</vuln:product>
      <vuln:product>cpe:/a:vmware:gsx_server:3.0_build_7592</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6j</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2.0.01</vuln:product>
      <vuln:product>cpe:/a:cisco:ciscoworks_common_services:2.2</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.2_rc2</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:::vsx-ng-ai</vuln:product>
      <vuln:product>cpe:/a:checkpoint:provider-1:4.1</vuln:product>
      <vuln:product>cpe:/a:neoteris:instant_virtual_extranet:3.2</vuln:product>
      <vuln:product>cpe:/a:cisco:css_secure_content_accelerator:2.0</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.7.1</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:7.10</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:500</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate_vpn_client:1.7.2</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.5.27</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sy</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.6-15::i386</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_securitycluster:2.5</vuln:product>
      <vuln:product>cpe:/h:avaya:s8500:r2.0.0</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:2.0::gx</vuln:product>
      <vuln:product>cpe:/a:vmware:gsx_server:2.5.1_build_5336</vuln:product>
      <vuln:product>cpe:/h:avaya:sg208:4.4</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0079</vuln:cve-id>
    <vuln:published-datetime>2004-11-23T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:32.253-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9779" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9779" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5770" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5770" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:975" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:975" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:870" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:870" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2621" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2621" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-078A.html" xml:lang="en">TA04-078A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/288574" xml:lang="en">VU#288574</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15505" xml:lang="en">openssl-dochangecipherspec-dos(15505)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uniras.gov.uk/vuls/2004/224012/index.htm" xml:lang="en">http://www.uniras.gov.uk/vuls/2004/224012/index.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2004/0012" xml:lang="en">2004-0012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.455961" xml:lang="en">SSA:2004-077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9899" xml:lang="en">9899</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-830.html" xml:lang="en">RHSA-2005:830</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-829.html" xml:lang="en">RHSA-2005:829</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-139.html" xml:lang="en">RHSA-2004:139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-121.html" xml:lang="en">RHSA-2004:121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-120.html" xml:lang="en">RHSA-2004:120</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2005-October/msg00087.html" xml:lang="en">FEDORA-2005-1042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openssl.org/news/secadv_20040317.txt" xml:lang="en">http://www.openssl.org/news/secadv_20040317.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2004_07_openssl.html" xml:lang="en">SuSE-SA:2004:007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html" xml:lang="en">ESA-20040317-003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-465" xml:lang="en">DSA-465</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml" xml:lang="en">20040317 Cisco OpenSSL Implementation Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-101.shtml" xml:lang="en">O-101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.lexmark.com/index?page=content&amp;id=TE88&amp;locale=EN&amp;userlocale=EN_US" xml:lang="en">http://support.lexmark.com/index?page=content&amp;id=TE88&amp;locale=EN&amp;userlocale=EN_US</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2005-239.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2005-239.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524" xml:lang="en">57524</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200403-03.xml" xml:lang="en">GLSA-200403-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18247" xml:lang="en">18247</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/17401" xml:lang="en">17401</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/17398" xml:lang="en">17398</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/17381" xml:lang="en">17381</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11139" xml:lang="en">11139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403806509920&amp;w=2" xml:lang="en">SSRT4717</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107953412903636&amp;w=2" xml:lang="en">20040317 New OpenSSL releases fix denial of service attacks [17 March 2004]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00045.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00045.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" xml:lang="en">APPLE-SA-2005-08-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" xml:lang="en">APPLE-SA-2005-08-17</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/updates/FEDORA-2004-095.shtml" xml:lang="en">FEDORA-2004-095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000834" xml:lang="en">CLA-2004:834</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt" xml:lang="en">SCOSA-2004.10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc" xml:lang="en">NetBSD-SA2004-005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:05.openssl.asc" xml:lang="en">FreeBSD-SA-04:05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:023" xml:lang="en">MDKSA-2004:023</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:975" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:975" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5770" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5770" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:870" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:870" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9779" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9779" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2621" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2621" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0080">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:andries_brouwer:util-linux:2.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:andries_brouwer:util-linux:2.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0080</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:28.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/801526" xml:lang="en">VU#801526</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-056.html" xml:lang="en">RHSA-2004:056</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9558" xml:lang="en">9558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15016" xml:lang="en">utillinux-information-leak(15016)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3796" xml:lang="en">3796</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200404-06.xml" xml:lang="en">GLSA-200404-06</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10773" xml:lang="en">10773</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108144719532385&amp;w=2" xml:lang="en">20040408 LNSA-#2004-0010: login may leak sensitive data</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108077689801698&amp;w=2" xml:lang="en">20040331 OpenLinux: util-linux could leak sensitive data</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040406-01-U" xml:lang="en">20040406-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc" xml:lang="en">20040201-01-U</vuln:reference>
    </vuln:references>
    <vuln:summary>The login program in util-linux 2.11 and earlier uses a pointer after it has been freed and reallocated, which could cause login to leak sensitive data.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0081">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:1.1_%283.005%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:2.1_%280.208%29"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:aaa_server"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:apache-based_web_server:2.0.43.00"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:apache-based_web_server:2.0.43.04"/>
        <cpe-lang:fact-ref name="cpe:/h:symantec:clientless_vpn_gateway_4400:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cisco:ciscoworks_common_management_foundation:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:ciscoworks_common_services:2.2"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:converged_communications_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg200:4.31.29"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg200:4.4"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg203:4.31.29"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg203:4.4"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg208"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg208:4.4"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg5:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg5:4.3"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg5:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.23"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:8.05"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::workstation_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.3"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2811%29e"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2811b%29e"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2811b%29e12"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2811b%29e14"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2813%29e9"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2819%29e1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%2814%29sy"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%2814%29sy1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sy"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2za"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.2.2"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.2.3"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.2.4"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:intuity_audix:::lx"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:intuity_audix:5.1.46"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:intuity_audix:s3210"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:intuity_audix:s3400"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:100_r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:10000_r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:2000_r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:5"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:500"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:5000_r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:5x"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:7500_r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:::vsx-ng-ai"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:2.0::gx"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:next_generation_fp0"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:next_generation_fp1"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:next_generation_fp2"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:provider-1:4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:provider-1:4.1:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:provider-1:4.1:sp2"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:provider-1:4.1:sp3"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:provider-1:4.1:sp4"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:vpn-1:next_generation"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:vpn-1:next_generation_fp0"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:vpn-1:next_generation_fp1"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:vpn-1:vsx_ng_with_application_intelligence"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:access_registrar"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:application_and_content_networking_software"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:css_secure_content_accelerator:1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:css_secure_content_accelerator:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:css11000_content_services_switch"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:okena_stormwatch:3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:pix_firewall:6.2.2_.111"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:threat_response"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:6.10"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:6.10_b4"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:7.1_0.1.02"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:7.1_0.2.06"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:7.10"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:7.10_.0.06s"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:7.2_0.0.03"/>
          <cpe-lang:fact-ref name="cpe:/a:hp:wbem:a.01.05.08"/>
          <cpe-lang:fact-ref name="cpe:/a:hp:wbem:a.02.00.00"/>
          <cpe-lang:fact-ref name="cpe:/a:hp:wbem:a.02.00.01"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.2.2"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.2_rc1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.2_rc2"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.3"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.3_rc1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.3_rc2"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.3_rc3"/>
          <cpe-lang:fact-ref name="cpe:/a:neoteris:instant_virtual_extranet:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:neoteris:instant_virtual_extranet:3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:neoteris:instant_virtual_extranet:3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:neoteris:instant_virtual_extranet:3.3"/>
          <cpe-lang:fact-ref name="cpe:/a:neoteris:instant_virtual_extranet:3.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.5"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.5.12a"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.5.27"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.7"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.7.1:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:imanager:1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:imanager:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6c"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6d"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6e"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6f"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6g"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6h"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6i"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6j"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6k"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta1"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta2"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta3"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7a"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7b"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7c"/>
          <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.6-15::i386"/>
          <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.6b-3::i386"/>
          <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.7a-2::i386"/>
          <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.7a-2::i386_dev"/>
          <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.7a-2::i386_perl"/>
          <cpe-lang:fact-ref name="cpe:/a:rsa:bsafe_ssl-j_sdk:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:rsa:bsafe_ssl-j_sdk:3.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:rsa:bsafe_ssl-j_sdk:3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.3"/>
          <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.4"/>
          <cpe-lang:fact-ref name="cpe:/a:sgi:propack:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:servercluster:2.5"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:servercluster:2.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_fullcluster:1_2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_fullcluster:1_3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_fullcluster:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_fullcluster:2.5"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_fullcluster:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_securitycluster:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_securitycluster:2.5"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_webcluster:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_webcluster:2.5"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.5.17"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.5.18"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.7"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.2"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.2.4"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate_vpn_client:1.7"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate_vpn_client:1.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate_vpn_client:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate_vpn_client:2.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate_vpn_client:2.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate_vpn_client:2.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:tarantella:tarantella_enterprise:3.20"/>
          <cpe-lang:fact-ref name="cpe:/a:tarantella:tarantella_enterprise:3.30"/>
          <cpe-lang:fact-ref name="cpe:/a:tarantella:tarantella_enterprise:3.40"/>
          <cpe-lang:fact-ref name="cpe:/a:vmware:gsx_server:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:vmware:gsx_server:2.0.1_build_2129"/>
          <cpe-lang:fact-ref name="cpe:/a:vmware:gsx_server:2.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:vmware:gsx_server:2.5.1_build_5336"/>
          <cpe-lang:fact-ref name="cpe:/a:vmware:gsx_server:3.0_build_7592"/>
          <cpe-lang:fact-ref name="cpe:/h:avaya:s8300:r2.0.0"/>
          <cpe-lang:fact-ref name="cpe:/h:avaya:s8300:r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/h:avaya:s8500:r2.0.0"/>
          <cpe-lang:fact-ref name="cpe:/h:avaya:s8500:r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/h:avaya:s8700:r2.0.0"/>
          <cpe-lang:fact-ref name="cpe:/h:avaya:s8700:r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/h:bluecoat:proxysg"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:content_services_switch_11500"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:gss_4480_global_site_selector"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:gss_4490_global_site_selector"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:mds_9000"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:secure_content_accelerator:10000"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2.0.01"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2.0.02"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2.0.03"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2.0.04"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2.1"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2.1.02"/>
          <cpe-lang:fact-ref name="cpe:/h:sun:crypto_accelerator_4000:1.0"/>
          <cpe-lang:fact-ref name="cpe:/o:bluecoat:cacheos_ca_sa:4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/o:bluecoat:cacheos_ca_sa:4.1.12"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.0"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.0%281%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.0%282%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.0%283%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.0%284%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.0%284.101%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.1%281%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.1%282%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.1%283%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.1%284%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.1%285%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.2"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.2%281%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.2%282%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.2%283%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.2%283.100%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.3"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.3%281%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.3%282%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.3%283.102%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.3%283.109%29"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta1</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:7.2_0.0.03</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::workstation_server</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.3%283.102%29</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2.1.02</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_fullcluster:1_3.0</vuln:product>
      <vuln:product>cpe:/a:vmware:gsx_server:2.0.1_build_2129</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2.0.04</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.1%282%29</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.5</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate_vpn_client:1.7</vuln:product>
      <vuln:product>cpe:/a:stonesoft:servercluster:2.5</vuln:product>
      <vuln:product>cpe:/h:symantec:clientless_vpn_gateway_4400:5.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:8.0</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.2%283.100%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.1%284%29</vuln:product>
      <vuln:product>cpe:/h:cisco:mds_9000</vuln:product>
      <vuln:product>cpe:/a:cisco:application_and_content_networking_software</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.0</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.7</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_webcluster:2.0</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2.1</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.2%281%29</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.2</vuln:product>
      <vuln:product>cpe:/a:vmware:gsx_server:2.5.1</vuln:product>
      <vuln:product>cpe:/h:avaya:sg200:4.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.9</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.3.1</vuln:product>
      <vuln:product>cpe:/h:hp:aaa_server</vuln:product>
      <vuln:product>cpe:/a:cisco:pix_firewall:6.2.2_.111</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate_vpn_client:2.0.7</vuln:product>
      <vuln:product>cpe:/a:rsa:bsafe_ssl-j_sdk:3.0</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module:1.1.3</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:2.0</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.0%283%29</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.5.18</vuln:product>
      <vuln:product>cpe:/h:bluecoat:proxysg</vuln:product>
      <vuln:product>cpe:/a:checkpoint:provider-1:4.1:sp1</vuln:product>
      <vuln:product>cpe:/a:neoteris:instant_virtual_extranet:3.0</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.2.1</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.6</vuln:product>
      <vuln:product>cpe:/h:avaya:sg5:4.4</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:8.05</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.7a-2::i386_dev</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.5.12a</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:7.10_.0.06s</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6f</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1:releng</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6c</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.3</vuln:product>
      <vuln:product>cpe:/a:avaya:intuity_audix:::lx</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.23</vuln:product>
      <vuln:product>cpe:/a:neoteris:instant_virtual_extranet:3.3.1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7a</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.2.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.2</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.3_rc2</vuln:product>
      <vuln:product>cpe:/a:hp:wbem:a.01.05.08</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.3_rc3</vuln:product>
      <vuln:product>cpe:/a:stonesoft:servercluster:2.5.2</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:100_r2.0.1</vuln:product>
      <vuln:product>cpe:/a:hp:wbem:a.02.00.01</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:1.5</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:3.0</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.6.3</vuln:product>
      <vuln:product>cpe:/h:avaya:sg5:4.3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%2814%29sy</vuln:product>
      <vuln:product>cpe:/a:rsa:bsafe_ssl-j_sdk:3.0.1</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:5</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_fullcluster:2.0</vuln:product>
      <vuln:product>cpe:/a:tarantella:tarantella_enterprise:3.20</vuln:product>
      <vuln:product>cpe:/a:checkpoint:vpn-1:next_generation_fp1</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.1.1</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module:2.1_%280.208%29</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.0.3</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.7.1</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_fullcluster:2.5</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.0.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1:release</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:5000_r2.0.1</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_fullcluster:3.0</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.3</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.1</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:2000_r2.0.1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2811b%29e</vuln:product>
      <vuln:product>cpe:/h:avaya:sg200:4.31.29</vuln:product>
      <vuln:product>cpe:/h:avaya:s8500:r2.0.1</vuln:product>
      <vuln:product>cpe:/a:cisco:css11000_content_services_switch</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2.0.02</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:next_generation_fp2</vuln:product>
      <vuln:product>cpe:/o:bluecoat:cacheos_ca_sa:4.1.12</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:4.0</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.5</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.1%283%29</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.3_rc1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2819%29e1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6d</vuln:product>
      <vuln:product>cpe:/a:checkpoint:provider-1:4.1:sp3</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.3</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.0%281%29</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.7.1:sp1</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate_vpn_client:2.0</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate_vpn_client:2.0.9</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.2.3</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6g</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:7500_r2.0.1</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:6.10_b4</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7c</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.2.2</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:7.1_0.2.06</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.0%284%29</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.3</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:7.1_0.1.02</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6k</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/a:avaya:intuity_audix:5.1.46</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.0%282%29</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.2.4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%2814%29sy1</vuln:product>
      <vuln:product>cpe:/h:hp:apache-based_web_server:2.0.43.04</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_fullcluster:1_2.0</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.9</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.2.4</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.7</vuln:product>
      <vuln:product>cpe:/a:vmware:gsx_server:2.0</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta3</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.2%283%29</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.1</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2</vuln:product>
      <vuln:product>cpe:/a:checkpoint:vpn-1:vsx_ng_with_application_intelligence</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:5x</vuln:product>
      <vuln:product>cpe:/a:rsa:bsafe_ssl-j_sdk:3.1</vuln:product>
      <vuln:product>cpe:/a:checkpoint:provider-1:4.1:sp4</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:10000_r2.0.1</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.2</vuln:product>
      <vuln:product>cpe:/a:cisco:ciscoworks_common_management_foundation:2.1</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_securitycluster:2.0</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.4</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.1%281%29</vuln:product>
      <vuln:product>cpe:/a:cisco:css_secure_content_accelerator:1.0</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.2.2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6e</vuln:product>
      <vuln:product>cpe:/o:bluecoat:cacheos_ca_sa:4.1.10</vuln:product>
      <vuln:product>cpe:/a:neoteris:instant_virtual_extranet:3.1</vuln:product>
      <vuln:product>cpe:/a:cisco:threat_response</vuln:product>
      <vuln:product>cpe:/h:cisco:call_manager</vuln:product>
      <vuln:product>cpe:/a:tarantella:tarantella_enterprise:3.30</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.3</vuln:product>
      <vuln:product>cpe:/a:checkpoint:vpn-1:next_generation_fp0</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.2</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:next_generation_fp1</vuln:product>
      <vuln:product>cpe:/a:cisco:access_registrar</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::advanced_server</vuln:product>
      <vuln:product>cpe:/h:sun:crypto_accelerator_4000:1.0</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.3%282%29</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_webcluster:2.5</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.3</vuln:product>
      <vuln:product>cpe:/h:avaya:sg203:4.31.29</vuln:product>
      <vuln:product>cpe:/h:hp:apache-based_web_server:2.0.43.00</vuln:product>
      <vuln:product>cpe:/a:checkpoint:vpn-1:next_generation</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.3</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.2_rc1</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.1%285%29</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2.0.03</vuln:product>
      <vuln:product>cpe:/h:avaya:s8300:r2.0.0</vuln:product>
      <vuln:product>cpe:/a:hp:wbem:a.02.00.00</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.6b-3::i386</vuln:product>
      <vuln:product>cpe:/a:neoteris:instant_virtual_extranet:3.3</vuln:product>
      <vuln:product>cpe:/h:avaya:converged_communications_server:2.0</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.7</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2811b%29e12</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.6.2</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.6.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.3%283.109%29</vuln:product>
      <vuln:product>cpe:/h:avaya:s8700:r2.0.1</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.3%281%29</vuln:product>
      <vuln:product>cpe:/a:cisco:okena_stormwatch:3.2</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module:1.1_%283.005%29</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8:releng</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2813%29e9</vuln:product>
      <vuln:product>cpe:/h:avaya:s8700:r2.0.0</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.3</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:next_generation_fp0</vuln:product>
      <vuln:product>cpe:/h:avaya:s8300:r2.0.1</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.2.1:release</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:3.0</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.7.2</vuln:product>
      <vuln:product>cpe:/a:avaya:intuity_audix:s3400</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6h</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7</vuln:product>
      <vuln:product>cpe:/a:avaya:intuity_audix:s3210</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2za</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate_vpn_client:2.0.8</vuln:product>
      <vuln:product>cpe:/h:cisco:gss_4480_global_site_selector</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:6.10</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.3.1</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.7a-2::i386</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.2%282%29</vuln:product>
      <vuln:product>cpe:/a:checkpoint:provider-1:4.1:sp2</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module:1.1.2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6i</vuln:product>
      <vuln:product>cpe:/h:avaya:sg5:4.2</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.1</vuln:product>
      <vuln:product>cpe:/h:cisco:gss_4490_global_site_selector</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.6</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2811b%29e14</vuln:product>
      <vuln:product>cpe:/h:avaya:sg208</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2811%29e</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7b</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.5.17</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.7a-2::i386_perl</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.0%284.101%29</vuln:product>
      <vuln:product>cpe:/h:cisco:secure_content_accelerator:10000</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.2.1</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.0</vuln:product>
      <vuln:product>cpe:/h:cisco:content_services_switch_11500</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.4</vuln:product>
      <vuln:product>cpe:/a:tarantella:tarantella_enterprise:3.40</vuln:product>
      <vuln:product>cpe:/h:avaya:sg203:4.4</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.4</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.0.1</vuln:product>
      <vuln:product>cpe:/a:vmware:gsx_server:3.0_build_7592</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6j</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2.0.01</vuln:product>
      <vuln:product>cpe:/a:cisco:ciscoworks_common_services:2.2</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.2_rc2</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:::vsx-ng-ai</vuln:product>
      <vuln:product>cpe:/a:checkpoint:provider-1:4.1</vuln:product>
      <vuln:product>cpe:/a:neoteris:instant_virtual_extranet:3.2</vuln:product>
      <vuln:product>cpe:/a:cisco:css_secure_content_accelerator:2.0</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.7.1</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:7.10</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:500</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate_vpn_client:1.7.2</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.5.27</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sy</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.6-15::i386</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_securitycluster:2.5</vuln:product>
      <vuln:product>cpe:/h:avaya:s8500:r2.0.0</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:2.0::gx</vuln:product>
      <vuln:product>cpe:/a:vmware:gsx_server:2.5.1_build_5336</vuln:product>
      <vuln:product>cpe:/h:avaya:sg208:4.4</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0081</vuln:cve-id>
    <vuln:published-datetime>2004-11-23T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:32.550-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11755" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11755" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:902" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:902" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:871" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:871" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-078A.html" xml:lang="en">TA04-078A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/465542" xml:lang="en">VU#465542</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15509" xml:lang="en">openssl-tls-dos(15509)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uniras.gov.uk/vuls/2004/224012/index.htm" xml:lang="en">http://www.uniras.gov.uk/vuls/2004/224012/index.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2004/0012" xml:lang="en">2004-0012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9899" xml:lang="en">9899</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-139.html" xml:lang="en">RHSA-2004:139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-121.html" xml:lang="en">RHSA-2004:121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-120.html" xml:lang="en">RHSA-2004:120</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html" xml:lang="en">ESA-20040317-003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-465" xml:lang="en">DSA-465</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml" xml:lang="en">20040317 Cisco OpenSSL Implementation Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524" xml:lang="en">57524</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200403-03.xml" xml:lang="en">GLSA-200403-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11139" xml:lang="en">11139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2004-119.html" xml:lang="en">RHSA-2004:119</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403850228012&amp;w=2" xml:lang="en">20040508 [FLSA-2004:1395] Updated OpenSSL resolves security vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107955049331965&amp;w=2" xml:lang="en">20040317 Re: New OpenSSL releases fix denial of service attacks [17  March 2004]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/updates/FEDORA-2004-095.shtml" xml:lang="en">FEDORA-2004-095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000834" xml:lang="en">CLA-2004:834</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040304-01-U.asc" xml:lang="en">20040304-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt" xml:lang="en">SCOSA-2004.10</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:871" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:871" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11755" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11755" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:902" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:902" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0082">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:samba:samba:3.0.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0082</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:29.147-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:827" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:827" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9637" xml:lang="en">9637</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-064.html" xml:lang="en">RHSA-2004:064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15132" xml:lang="en">samba-mksmbpasswd-gain-access(15132)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vuxml.org/freebsd/3388eff9-5d6e-11d8-80e3-0020ed76ef5a.html" xml:lang="en">http://www.vuxml.org/freebsd/3388eff9-5d6e-11d8-80e3-0020ed76ef5a.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://us1.samba.org/samba/ftp/WHATSNEW-3.0.2a.txt" xml:lang="en">http://us1.samba.org/samba/ftp/WHATSNEW-3.0.2a.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3919" xml:lang="en">3919</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-078.shtml" xml:lang="en">O-078</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:827" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:827" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10675" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10675" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0083">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1::errata"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:openbsd:openbsd:3.4</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.3</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1::errata</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.12</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.11</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0083</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:32.830-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9612" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9612" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:830" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:830" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:806" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:806" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/820006" xml:lang="en">VU#820006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9636" xml:lang="en">9636</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107644835523678&amp;w=2" xml:lang="en">20040210 iDEFENSESecurityAdvisory02.10.04: XFree86FontInformationFileBufferOverflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15130" xml:lang="en">xfree86-fontalias-bo(15130)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.xfree86.org/cvs/changes" xml:lang="en">http://www.xfree86.org/cvs/changes</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-061.html" xml:lang="en">RHSA-2004:061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-060.html" xml:lang="en">RHSA-2004:060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-059.html" xml:lang="en">RHSA-2004:059</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2004_06_xf86.html" xml:lang="en">SuSE-SA:2004:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=72" xml:lang="en">http://www.idefense.com/application/poi/display?id=72</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-443" xml:lang="en">DSA-443</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200402-02.xml" xml:lang="en">GLSA-200402-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053" xml:lang="en">SSA:2004-043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012" xml:lang="en">MDKSA-2004:012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57768-1" xml:lang="en">57768</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2" xml:lang="en">FLSA:2314</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107653324115914&amp;w=2" xml:lang="en">20040211 XFree86 vulnerability exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821" xml:lang="en">CLA-2004:821</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:830" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:830" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9612" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9612" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:806" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:806" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0084">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1::errata"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:openbsd:openbsd:3.4</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.3</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1::errata</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.12</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.11</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0084</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:32.970-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10405" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10405" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:831" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:831" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:807" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:807" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/667502" xml:lang="en">VU#667502</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9652" xml:lang="en">9652</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-061.html" xml:lang="en">RHSA-2004:061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-060.html" xml:lang="en">RHSA-2004:060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15200" xml:lang="en">xfree86-copyisolatin1lLowered-bo(15200)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053" xml:lang="en">SSA:2004-043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-059.html" xml:lang="en">RHSA-2004:059</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2004_06_xf86.html" xml:lang="en">SuSE-SA:2004:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=73" xml:lang="en">http://www.idefense.com/application/poi/display?id=73</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-443" xml:lang="en">DSA-443</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2" xml:lang="en">FLSA:2314</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821" xml:lang="en">CLA-2004:821</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012" xml:lang="en">MDKSA-2004:012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57768-1" xml:lang="en">57768</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107662833512775&amp;w=2" xml:lang="en">20040212 iDEFENSE Security Advisory 02.11.04: XFree86 Font Information File Buffer Overflow II</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:831" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:831" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10405" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10405" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:807" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:807" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0085">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0085</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:05.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14992" xml:lang="en">macosx-mail-undisclosed(14992)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9504" xml:lang="en">9504</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" xml:lang="en">APPLE-SA-2004-01-26</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the Mail application for Mac OS X 10.1.5 and 10.2.8 with unknown impact, a different vulnerability than CVE-2004-0086.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0086">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0086</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:05.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9504" xml:lang="en">9504</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" xml:lang="en">APPLE-SA-2004-01-26</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0087">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0087</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:05.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14997" xml:lang="en">macosx-configd-file-manipulation(14997)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9504" xml:lang="en">9504</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6819" xml:lang="en">6819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" xml:lang="en">APPLE-SA-2004-01-26</vuln:reference>
    </vuln:references>
    <vuln:summary>The System Configuration subsystem in Mac OS 10.2.8 and 10.3.2 allows local users to modify network settings, a different vulnerability than CVE-2004-0088.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0088">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0088</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:05.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9504" xml:lang="en">9504</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6820" xml:lang="en">6820</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" xml:lang="en">APPLE-SA-2004-01-26</vuln:reference>
    </vuln:references>
    <vuln:summary>The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a different vulnerability than CVE-2004-0087.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0089">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0089</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:06.367-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/902374" xml:lang="en">VU#902374</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9509" xml:lang="en">9509</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14968" xml:lang="en">macosx-trublue-environmentvariable-bo(14968)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6821" xml:lang="en">6821</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2004/a012704-1.txt" xml:lang="en">A012704-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" xml:lang="en">APPLE-SA-2004-01-26</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in TruBlueEnvironment in Mac OS X 10.3.x and 10.2.x allows local users to gain privileges via a long environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0090">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0090</vuln:cve-id>
    <vuln:published-datetime>2004-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:30.397-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-15T10:15:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9504" xml:lang="en">9504</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10723/" xml:lang="en">10723</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>AUSCERT</vuln:source>
      <vuln:reference href="http://www.auscert.org.au/render.html?it=3791&amp;cid=1" xml:lang="en">ESB-2004.0072</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" xml:lang="en">APPLE-SA-2004-01-26</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in Windows File Sharing for Mac OS X 10.1.5 through 10.3.2 does not "shutdown properly," which has unknown impact and attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0091">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.0_beta_2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jelsoft:vbulletin:3.0_beta_2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0091</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:06.507-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008780" xml:lang="en">1008780</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULN-DEV</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107488880317647&amp;w=2" xml:lang="en">20040123 RE: vBulletin Security Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULN-DEV</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107478592401619&amp;w=2" xml:lang="en">20040120 Re: vBulletin Security Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VULN-DEV</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107462499927040&amp;w=2" xml:lang="en">20040120 vBulletin Security Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107462349324945&amp;w=2" xml:lang="en">20040120 vBulletin Security Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  NOTE: this issue has been disputed by the vendor.  Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter.  NOTE: the vendor has disputed this issue, saying "There is no hidden field called 'reg_site', nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed.  We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft."</vuln:summary>
  </entry>
  <entry id="CVE-2004-0092">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0092</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:06.587-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9504" xml:lang="en">9504</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" xml:lang="en">APPLE-SA-2004-01-26</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0093">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1::errata"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1::errata</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.12</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.11</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0093</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:30.897-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-443" xml:lang="en">DSA-443</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15272" xml:lang="en">xfree86-glx-array-dos(15272)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9701" xml:lang="en">9701</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-152.html" xml:lang="en">RHSA-2004:152</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000824" xml:lang="en">CLSA-2004:824</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040406-01-U" xml:lang="en">20040406-01-U</vuln:reference>
    </vuln:references>
    <vuln:summary>XFree86 4.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an out-of-bounds array index when using the GLX extension and Direct Rendering Infrastructure (DRI).</vuln:summary>
  </entry>
  <entry id="CVE-2004-0094">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1::errata"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1::errata</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.12</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.11</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0094</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:31.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-443" xml:lang="en">DSA-443</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15273" xml:lang="en">xfree86-glx-integer-dos(15273)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9701" xml:lang="en">9701</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-152.html" xml:lang="en">RHSA-2004:152</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000824" xml:lang="en">CLSA-2004:824</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040406-01-U" xml:lang="en">20040406-01-U</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer signedness errors in XFree86 4.1.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code when using the GLX extension and Direct Rendering Infrastructure (DRI).</vuln:summary>
  </entry>
  <entry id="CVE-2004-0095">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:3.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:3.6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0095</vuln:cve-id>
    <vuln:published-datetime>2004-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:31.240-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9476" xml:lang="en">9476</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://download.nai.com/products/patches/ePO/v3.1.0/EPO3013.zip" xml:lang="en">http://download.nai.com/products/patches/ePO/v3.1.0/EPO3013.zip</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14989" xml:lang="en">epolicy-contentlength-post-dos(14989)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3744" xml:lang="en">3744</vuln:reference>
    </vuln:references>
    <vuln:summary>McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0096">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.7.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:mod_python:2.7.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0096</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:31.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.modpython.org/pipermail/mod_python/2004-January/014879.html" xml:lang="en">[mod_python] 20040122 [ANNOUNCE] Mod_python 2.7.10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-063.html" xml:lang="en">RHSA-2004:063</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-058.html" xml:lang="en">RHSA-2004:058</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200401-03.xml" xml:lang="en">GLSA-200401-03</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10467" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10467" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unknown vulnerability in mod_python 2.7.9 allows remote attackers to cause a denial of service (httpd crash) via a certain query string, a variant of CAN-2003-0973.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0097">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openh323_project:pwlib:1.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openh323_project:pwlib:1.6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0097</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:34.113-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10056" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10056" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:826" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:826" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:803" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:803" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/749342" xml:lang="en">VU#749342</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-2004-01.html" xml:lang="en">CA-2004-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-047.html" xml:lang="en">RHSA-2004:047</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-448" xml:lang="en">DSA-448</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15202" xml:lang="en">pwlib-message-dos(15202)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9406" xml:lang="en">9406</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10056" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10056" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:826" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:826" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:803" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:803" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0099">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2.1:release"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:5.2.1:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1:release</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0099</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:31.693-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9533" xml:lang="en">9533</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:01.mksnap_ffs.asc" xml:lang="en">FreeBSD-SA-04:01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15005" xml:lang="en">freebsd-mksnapffs-bypass-security(15005)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3790" xml:lang="en">3790</vuln:reference>
    </vuln:references>
    <vuln:summary>mksnap_ffs in FreeBSD 5.1 and 5.2 only sets the snapshot flag when creating a snapshot for a file system, which causes default values for other flags to be used, possibly disabling security-critical settings and allowing a local user to bypass intended access restrictions.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0103">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:linley_henzell:crawl:4.0.0_b23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:linley_henzell:crawl:4.0.0_b23</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0103</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:31.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-432" xml:lang="en">DSA-432</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15032" xml:lang="en">crawl-long-environment-bo(15032)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9566" xml:lang="en">9566</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10788/" xml:lang="en">10788</vuln:reference>
    </vuln:references>
    <vuln:summary>crawl before 4.0.0 beta23 does not properly "apply a size check" when copying a certain environment variable, which may allow local users to gain privileges, possibly as a result of a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0104">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:metamail_corporation:metamail:2.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux_advanced_workstation:2.1::itanium_processor"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sgi:propack:2.4</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation</vuln:product>
      <vuln:product>cpe:/a:metamail_corporation:metamail:2.7</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.3</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:linux_advanced_workstation:2.1::itanium_processor</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0104</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:07.133-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/518518" xml:lang="en">VU#518518</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9692" xml:lang="en">9692</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-073.html" xml:lang="en">RHSA-2004:073</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15259" xml:lang="en">metamail-printheader-format-string(15259)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15245" xml:lang="en">metamail-contenttype-format-string(15245)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-449" xml:lang="en">DSA-449</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10908" xml:lang="en">10908</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0041.html" xml:lang="en">20040218 metamail format string bugs and buffer overflows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734" xml:lang="en">SSA:2004-049</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:014" xml:lang="en">MDKSA-2004:014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-083.shtml" xml:lang="en">O-083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107713476911429&amp;w=2" xml:lang="en">20040218 metamail format string bugs and buffer overflows</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0105">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:metamail_corporation:metamail:2.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux_advanced_workstation:2.1::itanium_processor"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sgi:propack:2.4</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation</vuln:product>
      <vuln:product>cpe:/a:metamail_corporation:metamail:2.7</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.3</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:linux_advanced_workstation:2.1::itanium_processor</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0105</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:07.210-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/513062" xml:lang="en">VU#513062</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-073.html" xml:lang="en">RHSA-2004:073</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15258" xml:lang="en">metamail-splitmail-subject-bo(15258)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15247" xml:lang="en">metamail-printheader-nonascii-bo(15247)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-449" xml:lang="en">DSA-449</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10908" xml:lang="en">10908</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0041.html" xml:lang="en">20040218 metamail format string bugs and buffer overflows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734" xml:lang="en">SSA:2004-049</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9692" xml:lang="en">9692</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:014" xml:lang="en">MDKSA-2004:014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-083.shtml" xml:lang="en">O-083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107713476911429&amp;w=2" xml:lang="en">20040218 metamail format string bugs and buffer overflows</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0106">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.2.1::errata"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:openbsd:openbsd:3.4</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.3</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.1::errata</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.2.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.12</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.11</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.1.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0106</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:34.580-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11111" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11111" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:832" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:832" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:809" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:809" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053" xml:lang="en">SSA:2004-043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-061.html" xml:lang="en">RHSA-2004:061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-060.html" xml:lang="en">RHSA-2004:060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15206" xml:lang="en">xfree86-multiple-font-improper-handling(15206)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-059.html" xml:lang="en">RHSA-2004:059</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2004_06_xf86.html" xml:lang="en">SuSE-SA:2004:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-443" xml:lang="en">DSA-443</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012" xml:lang="en">MDKSA-2004:012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2" xml:lang="en">FLSA:2314</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821" xml:lang="en">CLA-2004:821</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11111" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11111" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:809" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:809" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:832" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:832" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0107">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:redhat:sysstat:4.0.7-3::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sysstat:sysstat:4.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:sysstat:sysstat:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sysstat:sysstat:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sysstat:sysstat:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sysstat:sysstat:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sysstat:sysstat:4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sysstat:sysstat:4.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sysstat:sysstat:4.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:sysstat:sysstat:5.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sysstat:sysstat:4.1.4</vuln:product>
      <vuln:product>cpe:/a:sysstat:sysstat:4.1.5</vuln:product>
      <vuln:product>cpe:/a:sysstat:sysstat:4.1.7</vuln:product>
      <vuln:product>cpe:/a:sysstat:sysstat:4.0.7</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.4</vuln:product>
      <vuln:product>cpe:/a:redhat:sysstat:4.0.7-3::i386</vuln:product>
      <vuln:product>cpe:/a:sysstat:sysstat:5.0.1</vuln:product>
      <vuln:product>cpe:/a:sysstat:sysstat:4.1.6</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.3</vuln:product>
      <vuln:product>cpe:/a:sysstat:sysstat:4.1.2</vuln:product>
      <vuln:product>cpe:/a:sysstat:sysstat:4.1.1</vuln:product>
      <vuln:product>cpe:/a:sysstat:sysstat:4.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0107</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:34.720-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10737" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10737" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:862" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:862" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:849" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:849" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9838" xml:lang="en">9838</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-053.html" xml:lang="en">RHSA-2004:053</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040302-01-U.asc" xml:lang="en">20040302-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15428" xml:lang="en">sysstat-post-trigger-symlink(15428)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-093.html" xml:lang="en">RHSA-2004:093</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6884" xml:lang="en">6884</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-097.shtml" xml:lang="en">O-097</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:862" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:862" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:849" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:849" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10737" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10737" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0108">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:redhat:sysstat:4.0.7-3::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sysstat:sysstat:4.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:sysstat:sysstat:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sysstat:sysstat:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sysstat:sysstat:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sysstat:sysstat:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sysstat:sysstat:4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sysstat:sysstat:4.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sysstat:sysstat:4.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:sysstat:sysstat:5.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sysstat:sysstat:4.1.4</vuln:product>
      <vuln:product>cpe:/a:sysstat:sysstat:4.1.5</vuln:product>
      <vuln:product>cpe:/a:sysstat:sysstat:4.1.7</vuln:product>
      <vuln:product>cpe:/a:sysstat:sysstat:4.0.7</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.4</vuln:product>
      <vuln:product>cpe:/a:redhat:sysstat:4.0.7-3::i386</vuln:product>
      <vuln:product>cpe:/a:sysstat:sysstat:5.0.1</vuln:product>
      <vuln:product>cpe:/a:sysstat:sysstat:4.1.6</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.3</vuln:product>
      <vuln:product>cpe:/a:sysstat:sysstat:4.1.2</vuln:product>
      <vuln:product>cpe:/a:sysstat:sysstat:4.1.1</vuln:product>
      <vuln:product>cpe:/a:sysstat:sysstat:4.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0108</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:32.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9844" xml:lang="en">9844</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-053.html" xml:lang="en">RHSA-2004:053</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040302-01-U.asc" xml:lang="en">20040302-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15437" xml:lang="en">sysstat-isag-symlink(15437)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-460" xml:lang="en">DSA-460</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9698" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9698" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The isag utility, which processes sysstat data, allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CAN-2004-0107.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0109">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0109</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:34.923-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10733" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10733" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:940" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:940" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html" xml:lang="en">ESA-20040428-004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2004-166.html" xml:lang="en">RHSA-2004:166</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213675028441&amp;w=2" xml:lang="en">2004-0020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040405-01-U.asc" xml:lang="en">20040405-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15866" xml:lang="en">linux-iso9660-bo(15866)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/2004/TLSA-2004-14.txt" xml:lang="en">TLSA-2004-14</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10141" xml:lang="en">10141</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-183.html" xml:lang="en">RHSA-2004:183</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-106.html" xml:lang="en">RHSA-2004:106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-105.html" xml:lang="en">RHSA-2004:105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2004_09_kernel.html" xml:lang="en">SuSE-SA:2004:009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=101&amp;type=vulnerabilities" xml:lang="en">http://www.idefense.com/application/poi/display?id=101&amp;type=vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-495" xml:lang="en">DSA-495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-491" xml:lang="en">DSA-491</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-489" xml:lang="en">DSA-489</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-482" xml:lang="en">DSA-482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-481" xml:lang="en">DSA-481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-480" xml:lang="en">DSA-480</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-479" xml:lang="en">DSA-479</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-127.shtml" xml:lang="en">O-127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-121.shtml" xml:lang="en">O-121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200407-02.xml" xml:lang="en">GLSA-200407-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/12003" xml:lang="en">12003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11986" xml:lang="en">11986</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11891" xml:lang="en">11891</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11861" xml:lang="en">11861</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11626" xml:lang="en">11626</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11518" xml:lang="en">11518</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11494" xml:lang="en">11494</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11486" xml:lang="en">11486</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11470" xml:lang="en">11470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11469" xml:lang="en">11469</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11464" xml:lang="en">11464</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11373" xml:lang="en">11373</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11362" xml:lang="en">11362</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11361" xml:lang="en">11361</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846" xml:lang="en">CLA-2004:846</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc" xml:lang="en">20040504-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029" xml:lang="en">MDKSA-2004:029</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:940" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:940" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10733" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10733" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x, allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0110">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:xmlsoft:libxml:1.8.17"/>
        <cpe-lang:fact-ref name="cpe:/a:xmlsoft:libxml2:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/a:xmlsoft:libxml2:2.4.23"/>
        <cpe-lang:fact-ref name="cpe:/a:xmlsoft:libxml2:2.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:xmlsoft:libxml2:2.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:xmlsoft:libxml2:2.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:xmlsoft:libxml2:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xmlsoft:libxml2:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xmlsoft:libxml2:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:xmlsoft:libxml2:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:xmlsoft:libxml2:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:xmlsoft:libxml2:2.6.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xmlsoft:libxml2:2.4.19</vuln:product>
      <vuln:product>cpe:/a:xmlsoft:libxml2:2.5.4</vuln:product>
      <vuln:product>cpe:/a:xmlsoft:libxml2:2.5.11</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.4</vuln:product>
      <vuln:product>cpe:/a:xmlsoft:libxml2:2.5.10</vuln:product>
      <vuln:product>cpe:/a:xmlsoft:libxml2:2.6.5</vuln:product>
      <vuln:product>cpe:/a:xmlsoft:libxml:1.8.17</vuln:product>
      <vuln:product>cpe:/a:xmlsoft:libxml2:2.6.2</vuln:product>
      <vuln:product>cpe:/a:xmlsoft:libxml2:2.4.23</vuln:product>
      <vuln:product>cpe:/a:xmlsoft:libxml2:2.6.3</vuln:product>
      <vuln:product>cpe:/a:xmlsoft:libxml2:2.6.0</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.3</vuln:product>
      <vuln:product>cpe:/a:xmlsoft:libxml2:2.6.4</vuln:product>
      <vuln:product>cpe:/a:xmlsoft:libxml2:2.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0110</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:35.143-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11626" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11626" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:875" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:875" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:833" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:833" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/493966" xml:lang="en">VU#493966</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15301" xml:lang="en">libxml2-nanohttp-bo(15301)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9718" xml:lang="en">9718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2004-090.html" xml:lang="en">RHSA-2004:090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107851606605420&amp;w=2" xml:lang="en">20040305 [OpenPKG-SA-2004.003] OpenPKG Security Advisory (libxml)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15302" xml:lang="en">libxml2-nanoftp-bo(15302)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-091.html" xml:lang="en">RHSA-2004:091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-455" xml:lang="en">DSA-455</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-086.shtml" xml:lang="en">O-086</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200403-01.xml" xml:lang="en">GLSA-200403-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10958/" xml:lang="en">10958</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.xmlsoft.org/news.html" xml:lang="en">http://www.xmlsoft.org/news.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-650.html" xml:lang="en">RHSA-2004:650</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2005_01_sr.html" xml:lang="en">SUSE-SR:2005:001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107860178228804&amp;w=2" xml:lang="en">20040306 TSLSA-2004-0010 - libxml2</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:875" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:875" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:833" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:833" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11626" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11626" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0111">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdkpixbuf:0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gdkpixbuf:0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:gdk_pixbuf:0.18.0-7::i386"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:gdk_pixbuf:0.18.0-7::i386_dev"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:gdk_pixbuf:0.18.0-7::i386_gnome"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::advanced_servers"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux_advanced_workstation:2.1::itanium_processor"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::workstation</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::advanced_servers</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation</vuln:product>
      <vuln:product>cpe:/a:gnome:gdkpixbuf:0.18</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server</vuln:product>
      <vuln:product>cpe:/o:redhat:linux_advanced_workstation:2.1::itanium_processor</vuln:product>
      <vuln:product>cpe:/a:redhat:gdk_pixbuf:0.18.0-7::i386_dev</vuln:product>
      <vuln:product>cpe:/a:redhat:gdk_pixbuf:0.18.0-7::i386</vuln:product>
      <vuln:product>cpe:/a:gnome:gdkpixbuf:0.20</vuln:product>
      <vuln:product>cpe:/a:redhat:gdk_pixbuf:0.18.0-7::i386_gnome</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.4</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.3</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0111</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:09.210-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:846" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:846" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:845" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:845" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9842" xml:lang="en">9842</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-103.html" xml:lang="en">RHSA-2004:103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://bugzilla.fedora.us/show_bug.cgi?id=2005" xml:lang="en">FLSA:2005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15426" xml:lang="en">gdk-pixbuf-bitmap-dos(15426)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-102.html" xml:lang="en">RHSA-2004:102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:020" xml:lang="en">MDKSA-2004:020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-464" xml:lang="en">DSA-464</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10574" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10574" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:845" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:845" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:846" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:846" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0112">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:1.1_%283.005%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:2.1_%280.208%29"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:aaa_server"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:apache-based_web_server:2.0.43.00"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:apache-based_web_server:2.0.43.04"/>
        <cpe-lang:fact-ref name="cpe:/h:symantec:clientless_vpn_gateway_4400:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cisco:ciscoworks_common_management_foundation:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:ciscoworks_common_services:2.2"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:converged_communications_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg200:4.31.29"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg200:4.4"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg203:4.31.29"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg203:4.4"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg208"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg208:4.4"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg5:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg5:4.3"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:sg5:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.23"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:8.05"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::workstation_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.3"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2811%29e"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2811b%29e"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2811b%29e12"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2811b%29e14"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2813%29e9"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1%2819%29e1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%2814%29sy"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%2814%29sy1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sy"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2za"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.2.2"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.2.3"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.2.4"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:4d:webstar:5.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:intuity_audix:::lx"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:intuity_audix:5.1.46"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:intuity_audix:s3210"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:intuity_audix:s3400"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:100_r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:10000_r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:2000_r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:5"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:500"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:5000_r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:5x"/>
          <cpe-lang:fact-ref name="cpe:/a:avaya:vsu:7500_r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:::vsx-ng-ai"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:2.0::gx"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:next_generation_fp0"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:next_generation_fp1"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:firewall-1:next_generation_fp2"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:provider-1:4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:provider-1:4.1:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:provider-1:4.1:sp2"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:provider-1:4.1:sp3"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:provider-1:4.1:sp4"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:vpn-1:next_generation_fp0"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:vpn-1:next_generation_fp1"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:vpn-1:next_generation_fp2"/>
          <cpe-lang:fact-ref name="cpe:/a:checkpoint:vpn-1:vsx_ng_with_application_intelligence"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:access_registrar"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:application_and_content_networking_software"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:css_secure_content_accelerator:1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:css_secure_content_accelerator:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:css11000_content_services_switch"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:okena_stormwatch:3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:pix_firewall:6.2.2_.111"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:threat_response"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:6.10"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:6.10_b4"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:7.1_0.1.02"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:7.1_0.2.06"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:7.10"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:7.10_.0.06s"/>
          <cpe-lang:fact-ref name="cpe:/a:cisco:webns:7.2_0.0.03"/>
          <cpe-lang:fact-ref name="cpe:/a:hp:wbem:a.01.05.08"/>
          <cpe-lang:fact-ref name="cpe:/a:hp:wbem:a.02.00.00"/>
          <cpe-lang:fact-ref name="cpe:/a:hp:wbem:a.02.00.01"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.2.2"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.2_rc1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.2_rc2"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.3"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.3_rc1"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.3_rc2"/>
          <cpe-lang:fact-ref name="cpe:/a:lite:speed_technologies_litespeed_web_server:1.3_rc3"/>
          <cpe-lang:fact-ref name="cpe:/a:neoteris:instant_virtual_extranet:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:neoteris:instant_virtual_extranet:3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:neoteris:instant_virtual_extranet:3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:neoteris:instant_virtual_extranet:3.3"/>
          <cpe-lang:fact-ref name="cpe:/a:neoteris:instant_virtual_extranet:3.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.5"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.5.12a"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.5.27"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.7"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:edirectory:8.7.1:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:imanager:1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:novell:imanager:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6c"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6d"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6e"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6f"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6g"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6h"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6i"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6j"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6k"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta1"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta2"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta3"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7a"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7b"/>
          <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7c"/>
          <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.6-15::i386"/>
          <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.6b-3::i386"/>
          <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.7a-2::i386"/>
          <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.7a-2::i386_dev"/>
          <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.7a-2::i386_perl"/>
          <cpe-lang:fact-ref name="cpe:/a:rsa:bsafe_ssl-j_sdk:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:rsa:bsafe_ssl-j_sdk:3.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:rsa:bsafe_ssl-j_sdk:3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.3"/>
          <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.4"/>
          <cpe-lang:fact-ref name="cpe:/a:sgi:propack:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:servercluster:2.5"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:servercluster:2.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_fullcluster:1_2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_fullcluster:1_3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_fullcluster:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_fullcluster:2.5"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_fullcluster:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_securitycluster:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_securitycluster:2.5"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_webcluster:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonebeat_webcluster:2.5"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.5.17"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.5.18"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.7"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:1.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.2"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:stonesoft:stonegate:2.2.4"/>
          <cpe-lang:fact-ref name="cpe:/a:tarantella:tarantella_enterprise:3.20"/>
          <cpe-lang:fact-ref name="cpe:/a:tarantella:tarantella_enterprise:3.30"/>
          <cpe-lang:fact-ref name="cpe:/a:tarantella:tarantella_enterprise:3.40"/>
          <cpe-lang:fact-ref name="cpe:/a:vmware:gsx_server:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:vmware:gsx_server:2.0.1_build_2129"/>
          <cpe-lang:fact-ref name="cpe:/a:vmware:gsx_server:2.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:vmware:gsx_server:2.5.1_build_5336"/>
          <cpe-lang:fact-ref name="cpe:/a:vmware:gsx_server:3.0_build_7592"/>
          <cpe-lang:fact-ref name="cpe:/h:avaya:s8300:r2.0.0"/>
          <cpe-lang:fact-ref name="cpe:/h:avaya:s8300:r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/h:avaya:s8500:r2.0.0"/>
          <cpe-lang:fact-ref name="cpe:/h:avaya:s8500:r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/h:avaya:s8700:r2.0.0"/>
          <cpe-lang:fact-ref name="cpe:/h:avaya:s8700:r2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/h:bluecoat:proxysg"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:call_manager"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:content_services_switch_11500"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:gss_4480_global_site_selector"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:gss_4490_global_site_selector"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:mds_9000"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:secure_content_accelerator:10000"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2.0.01"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2.0.02"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2.0.03"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2.0.04"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2.1"/>
          <cpe-lang:fact-ref name="cpe:/h:securecomputing:sidewinder:5.2.1.02"/>
          <cpe-lang:fact-ref name="cpe:/h:sun:crypto_accelerator_4000:1.0"/>
          <cpe-lang:fact-ref name="cpe:/o:bluecoat:cacheos_ca_sa:4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/o:bluecoat:cacheos_ca_sa:4.1.12"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.0"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.0%281%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.0%282%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.0%283%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.0%284%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.0%284.101%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.1"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.1%281%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.1%282%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.1%283%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.1%284%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.1%285%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.2"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.2%281%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.2%282%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.2%283%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.2%283.100%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.3"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.3%281%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.3%282%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.3%283.102%29"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:6.3%283.109%29"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta1</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:7.2_0.0.03</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::workstation_server</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.3%283.102%29</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2.1.02</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_fullcluster:1_3.0</vuln:product>
      <vuln:product>cpe:/a:vmware:gsx_server:2.0.1_build_2129</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2.0.04</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.1%282%29</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.5</vuln:product>
      <vuln:product>cpe:/a:stonesoft:servercluster:2.5</vuln:product>
      <vuln:product>cpe:/h:symantec:clientless_vpn_gateway_4400:5.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:8.0</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.2%283.100%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.1%284%29</vuln:product>
      <vuln:product>cpe:/h:cisco:mds_9000</vuln:product>
      <vuln:product>cpe:/a:cisco:application_and_content_networking_software</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.0</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.7</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_webcluster:2.0</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2.1</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.2%281%29</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.2</vuln:product>
      <vuln:product>cpe:/a:vmware:gsx_server:2.5.1</vuln:product>
      <vuln:product>cpe:/h:avaya:sg200:4.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.9</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.3.1</vuln:product>
      <vuln:product>cpe:/h:hp:aaa_server</vuln:product>
      <vuln:product>cpe:/a:cisco:pix_firewall:6.2.2_.111</vuln:product>
      <vuln:product>cpe:/a:rsa:bsafe_ssl-j_sdk:3.0</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module:1.1.3</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:2.0</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.0%283%29</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.5.18</vuln:product>
      <vuln:product>cpe:/h:bluecoat:proxysg</vuln:product>
      <vuln:product>cpe:/a:checkpoint:provider-1:4.1:sp1</vuln:product>
      <vuln:product>cpe:/a:neoteris:instant_virtual_extranet:3.0</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.2.1</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.6</vuln:product>
      <vuln:product>cpe:/h:avaya:sg5:4.4</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:8.05</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.7a-2::i386_dev</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.5.12a</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:7.10_.0.06s</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6f</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1:releng</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6c</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.3</vuln:product>
      <vuln:product>cpe:/a:avaya:intuity_audix:::lx</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.23</vuln:product>
      <vuln:product>cpe:/a:neoteris:instant_virtual_extranet:3.3.1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7a</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.2.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.2</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.3_rc2</vuln:product>
      <vuln:product>cpe:/a:hp:wbem:a.01.05.08</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.3_rc3</vuln:product>
      <vuln:product>cpe:/a:stonesoft:servercluster:2.5.2</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:100_r2.0.1</vuln:product>
      <vuln:product>cpe:/a:hp:wbem:a.02.00.01</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:1.5</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:3.0</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.6.3</vuln:product>
      <vuln:product>cpe:/h:avaya:sg5:4.3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%2814%29sy</vuln:product>
      <vuln:product>cpe:/a:rsa:bsafe_ssl-j_sdk:3.0.1</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:5</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_fullcluster:2.0</vuln:product>
      <vuln:product>cpe:/a:tarantella:tarantella_enterprise:3.20</vuln:product>
      <vuln:product>cpe:/a:checkpoint:vpn-1:next_generation_fp1</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.1.1</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module:2.1_%280.208%29</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.0.3</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.7.1</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_fullcluster:2.5</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.0.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1:release</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:5000_r2.0.1</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_fullcluster:3.0</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.3</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.1</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:2000_r2.0.1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2811b%29e</vuln:product>
      <vuln:product>cpe:/h:avaya:sg200:4.31.29</vuln:product>
      <vuln:product>cpe:/h:avaya:s8500:r2.0.1</vuln:product>
      <vuln:product>cpe:/a:cisco:css11000_content_services_switch</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2.0.02</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:next_generation_fp2</vuln:product>
      <vuln:product>cpe:/o:bluecoat:cacheos_ca_sa:4.1.12</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:4.0</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.5</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.1%283%29</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.3_rc1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2819%29e1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6d</vuln:product>
      <vuln:product>cpe:/a:checkpoint:provider-1:4.1:sp3</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.3</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.0%281%29</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.7.1:sp1</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.2.3</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6g</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:7500_r2.0.1</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:6.10_b4</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7c</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.2.2</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:7.1_0.2.06</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.0%284%29</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.3</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:7.1_0.1.02</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6k</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/a:avaya:intuity_audix:5.1.46</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.0%282%29</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.2.4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%2814%29sy1</vuln:product>
      <vuln:product>cpe:/h:hp:apache-based_web_server:2.0.43.04</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_fullcluster:1_2.0</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.9</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.2.4</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.7</vuln:product>
      <vuln:product>cpe:/a:vmware:gsx_server:2.0</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta3</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.2%283%29</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.1</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2</vuln:product>
      <vuln:product>cpe:/a:checkpoint:vpn-1:vsx_ng_with_application_intelligence</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:5x</vuln:product>
      <vuln:product>cpe:/a:rsa:bsafe_ssl-j_sdk:3.1</vuln:product>
      <vuln:product>cpe:/a:checkpoint:provider-1:4.1:sp4</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:10000_r2.0.1</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.2</vuln:product>
      <vuln:product>cpe:/a:cisco:ciscoworks_common_management_foundation:2.1</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_securitycluster:2.0</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.4</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.1%281%29</vuln:product>
      <vuln:product>cpe:/a:cisco:css_secure_content_accelerator:1.0</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.2.2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6e</vuln:product>
      <vuln:product>cpe:/o:bluecoat:cacheos_ca_sa:4.1.10</vuln:product>
      <vuln:product>cpe:/a:neoteris:instant_virtual_extranet:3.1</vuln:product>
      <vuln:product>cpe:/a:cisco:threat_response</vuln:product>
      <vuln:product>cpe:/h:cisco:call_manager</vuln:product>
      <vuln:product>cpe:/a:checkpoint:vpn-1:next_generation_fp2</vuln:product>
      <vuln:product>cpe:/a:tarantella:tarantella_enterprise:3.30</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.3</vuln:product>
      <vuln:product>cpe:/a:checkpoint:vpn-1:next_generation_fp0</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.2</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:next_generation_fp1</vuln:product>
      <vuln:product>cpe:/a:cisco:access_registrar</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::advanced_server</vuln:product>
      <vuln:product>cpe:/h:sun:crypto_accelerator_4000:1.0</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.3%282%29</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_webcluster:2.5</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.3</vuln:product>
      <vuln:product>cpe:/h:avaya:sg203:4.31.29</vuln:product>
      <vuln:product>cpe:/h:hp:apache-based_web_server:2.0.43.00</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.3</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.2_rc1</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.1%285%29</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2.0.03</vuln:product>
      <vuln:product>cpe:/h:avaya:s8300:r2.0.0</vuln:product>
      <vuln:product>cpe:/a:hp:wbem:a.02.00.00</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.6b-3::i386</vuln:product>
      <vuln:product>cpe:/a:neoteris:instant_virtual_extranet:3.3</vuln:product>
      <vuln:product>cpe:/h:avaya:converged_communications_server:2.0</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.7</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2811b%29e12</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.6.2</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.6.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.3%283.109%29</vuln:product>
      <vuln:product>cpe:/h:avaya:s8700:r2.0.1</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.3%281%29</vuln:product>
      <vuln:product>cpe:/a:cisco:okena_stormwatch:3.2</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module:1.1_%283.005%29</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8:releng</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2813%29e9</vuln:product>
      <vuln:product>cpe:/h:avaya:s8700:r2.0.0</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.3</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:next_generation_fp0</vuln:product>
      <vuln:product>cpe:/h:avaya:s8300:r2.0.1</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.2.1:release</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:3.0</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.7.2</vuln:product>
      <vuln:product>cpe:/a:avaya:intuity_audix:s3400</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6h</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7</vuln:product>
      <vuln:product>cpe:/a:avaya:intuity_audix:s3210</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2za</vuln:product>
      <vuln:product>cpe:/h:cisco:gss_4480_global_site_selector</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:6.10</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/a:4d:webstar:5.3.1</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.7a-2::i386</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.2%282%29</vuln:product>
      <vuln:product>cpe:/a:checkpoint:provider-1:4.1:sp2</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module:1.1.2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6i</vuln:product>
      <vuln:product>cpe:/h:avaya:sg5:4.2</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.1</vuln:product>
      <vuln:product>cpe:/h:cisco:gss_4490_global_site_selector</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.6</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2811b%29e14</vuln:product>
      <vuln:product>cpe:/h:avaya:sg208</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1%2811%29e</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7b</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:1.5.17</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.7a-2::i386_perl</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.0%284.101%29</vuln:product>
      <vuln:product>cpe:/h:cisco:secure_content_accelerator:10000</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.2.1</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:6.0</vuln:product>
      <vuln:product>cpe:/h:cisco:content_services_switch_11500</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonegate:2.0.4</vuln:product>
      <vuln:product>cpe:/a:tarantella:tarantella_enterprise:3.40</vuln:product>
      <vuln:product>cpe:/h:avaya:sg203:4.4</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.4</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.0.1</vuln:product>
      <vuln:product>cpe:/a:vmware:gsx_server:3.0_build_7592</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6j</vuln:product>
      <vuln:product>cpe:/h:securecomputing:sidewinder:5.2.0.01</vuln:product>
      <vuln:product>cpe:/a:cisco:ciscoworks_common_services:2.2</vuln:product>
      <vuln:product>cpe:/a:lite:speed_technologies_litespeed_web_server:1.2_rc2</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:::vsx-ng-ai</vuln:product>
      <vuln:product>cpe:/a:checkpoint:provider-1:4.1</vuln:product>
      <vuln:product>cpe:/a:neoteris:instant_virtual_extranet:3.2</vuln:product>
      <vuln:product>cpe:/a:cisco:css_secure_content_accelerator:2.0</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.7.1</vuln:product>
      <vuln:product>cpe:/a:cisco:webns:7.10</vuln:product>
      <vuln:product>cpe:/a:avaya:vsu:500</vuln:product>
      <vuln:product>cpe:/a:novell:edirectory:8.5.27</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sy</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.6-15::i386</vuln:product>
      <vuln:product>cpe:/a:stonesoft:stonebeat_securitycluster:2.5</vuln:product>
      <vuln:product>cpe:/h:avaya:s8500:r2.0.0</vuln:product>
      <vuln:product>cpe:/a:checkpoint:firewall-1:2.0::gx</vuln:product>
      <vuln:product>cpe:/a:vmware:gsx_server:2.5.1_build_5336</vuln:product>
      <vuln:product>cpe:/h:avaya:sg208:4.4</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0112</vuln:cve-id>
    <vuln:published-datetime>2004-11-23T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:35.377-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9580" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9580" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:928" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:928" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1049" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1049" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-078A.html" xml:lang="en">TA04-078A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/484726" xml:lang="en">VU#484726</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15508" xml:lang="en">openssl-kerberos-ciphersuites-dos(15508)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uniras.gov.uk/vuls/2004/224012/index.htm" xml:lang="en">http://www.uniras.gov.uk/vuls/2004/224012/index.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2004/0012" xml:lang="en">2004-0012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.455961" xml:lang="en">SSA:2004-077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9899" xml:lang="en">9899</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-121.html" xml:lang="en">RHSA-2004:121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-120.html" xml:lang="en">RHSA-2004:120</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openssl.org/news/secadv_20040317.txt" xml:lang="en">http://www.openssl.org/news/secadv_20040317.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2004_07_openssl.html" xml:lang="en">SuSE-SA:2004:007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml" xml:lang="en">20040317 Cisco OpenSSL Implementation Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-101.shtml" xml:lang="en">O-101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524" xml:lang="en">57524</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200403-03.xml" xml:lang="en">GLSA-200403-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11139" xml:lang="en">11139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403806509920&amp;w=2" xml:lang="en">SSRT4717</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107953412903636&amp;w=2" xml:lang="en">20040317 New OpenSSL releases fix denial of service attacks [17 March 2004]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.apple.com/mhonarc/security-announce/msg00045.html" xml:lang="en">http://lists.apple.com/mhonarc/security-announce/msg00045.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" xml:lang="en">APPLE-SA-2005-08-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" xml:lang="en">APPLE-SA-2005-08-17</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=61798" xml:lang="en">http://docs.info.apple.com/article.html?artnum=61798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000834" xml:lang="en">CLA-2004:834</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt" xml:lang="en">SCOSA-2004.10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc" xml:lang="en">NetBSD-SA2004-005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:023" xml:lang="en">MDKSA-2004:023</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:928" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:928" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9580" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9580" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1049" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1049" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0113">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.35"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.44"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.45"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.46"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.47"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.48"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:2.0.47</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.48</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.35</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.45</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.44</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.46</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0113</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:09.367-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:876" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:876" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9826" xml:lang="en">9826</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15419" xml:lang="en">apache-modssl-plain-dos(15419)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.apacheweek.com/features/security-20" xml:lang="en">http://www.apacheweek.com/features/security-20</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=apache-cvs&amp;m=107869699329638" xml:lang="en">[apache-cvs] 20040307 cvs commit: httpd-2.0/modules/ssl ssl_engine_io.c</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2004/0017" xml:lang="en">2004-0017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-182.html" xml:lang="en">RHSA-2004:182</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-084.html" xml:lang="en">RHSA-2004:084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/4182" xml:lang="en">4182</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:043" xml:lang="en">MDKSA-2004:043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200403-04.xml" xml:lang="en">GLSA-200403-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108731648532365&amp;w=2" xml:lang="en">SSRT4717</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2" xml:lang="en">APPLE-SA-2004-05-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108034113406858&amp;w=2" xml:lang="en">20040325 LNSA-#2004-0006: bug workaround for Apache 2.0.48</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://issues.apache.org/bugzilla/show_bug.cgi?id=27106" xml:lang="en">http://issues.apache.org/bugzilla/show_bug.cgi?id=27106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000839" xml:lang="en">CLSA-2004:839</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:876" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:876" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9676" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9676" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0114">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:openbsd:openbsd:2.6</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0114</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:34.490-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15061" xml:lang="en">bsd-shmat-gain-privileges(15061)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9586" xml:lang="en">9586</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:02.shmat.asc" xml:lang="en">FreeBSD-SA-04:02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.pine.nl/press/pine-cert-20040201.txt" xml:lang="en">http://www.pine.nl/press/pine-cert-20040201.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107608375207601&amp;w=2" xml:lang="en">20040205 [PINE-CERT-20040201] reference count overflow in shmat()</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3836" xml:lang="en">3836</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata33.html#sysvshm" xml:lang="en">http://www.openbsd.org/errata33.html#sysvshm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-004.txt.asc" xml:lang="en">NetBSD-SA2004-004</vuln:reference>
    </vuln:references>
    <vuln:summary>The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment's reference count when the vm_map_find function fails, which could allow local users to gain read or write access to a portion of kernel memory and gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0115">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:virtual_pc:6.0::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:virtual_pc:6.1::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:virtual_pc:6.2::mac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:virtual_pc:6.1::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:virtual_pc:6.0::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:virtual_pc:6.2::mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0115</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:34.647-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9632" xml:lang="en">9632</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms04-005.asp" xml:lang="en">MS04-005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2004/a021004-1.txt" xml:lang="en">A021004-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15113" xml:lang="en">virtual-pc-gain-privileges(15113)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3893" xml:lang="en">3893</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-076.shtml" xml:lang="en">O-076</vuln:reference>
    </vuln:references>
    <vuln:summary>VirtualPC_Services in Microsoft Virtual PC for Mac 6.0 through 6.1 allows local attackers to truncate and overwrite arbitrary files, and execute arbitrary code, via a symlink attack on the VPCServices_Log temporary file.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0116">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0116</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:09.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:958" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:958" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:957" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:957" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:955" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:955" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/417052" xml:lang="en">VU#417052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" xml:lang="en">TA04-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>EEYE</vuln:source>
      <vuln:reference href="http://www.eeye.com/html/Research/Advisories/AD20040413A.html" xml:lang="en">AD20040413A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms04-012.asp" xml:lang="en">MS04-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15708" xml:lang="en">win-rpcss-rpcmessage-dos(15708)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10127" xml:lang="en">10127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-115.shtml" xml:lang="en">O-115</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/alerts/2004/Apr/1009758.html" xml:lang="en">1009758</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11065/" xml:lang="en">11065</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:958" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:958" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:955" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:955" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:957" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:957" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0117">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:netmeeting:3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:netmeeting:3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0117</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:09.647-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:964" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:964" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:946" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:946" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:907" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:907" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/353956" xml:lang="en">VU#353956</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" xml:lang="en">TA04-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp" xml:lang="en">MS04-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15710" xml:lang="en">win-h323-bo(15710)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-114.shtml" xml:lang="en">O-114</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:946" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:946" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:964" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:964" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:907" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:907" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0118">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0118</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:09.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1718" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1718" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1512" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1512" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/783748" xml:lang="en">VU#783748</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" xml:lang="en">TA04-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp" xml:lang="en">MS04-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>EEYE</vuln:source>
      <vuln:reference href="http://www.eeye.com/html/Research/Advisories/AD20040413E.html" xml:lang="en">AD20040413E</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020070.html" xml:lang="en">20040413 EEYE: Windows VDM TIB Local Privilege Escalation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15714" xml:lang="en">win-vdm-gain-privileges(15714)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10117" xml:lang="en">10117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-114.shtml" xml:lang="en">O-114</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1718" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1718" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1512" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1512" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0119">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0119</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:09.790-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1997" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1997" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1962" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1962" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1808" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1808" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/638548" xml:lang="en">VU#638548</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" xml:lang="en">TA04-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp" xml:lang="en">MS04-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0081.html" xml:lang="en">20040414 NSFOCUS SA2004-01 : DoS Vulnerability in Microsoft Windows SPNEGO Protocol Decoding</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15715" xml:lang="en">win-spp-bo(15715)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10113" xml:lang="en">10113</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-114.shtml" xml:lang="en">O-114</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1808" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1808" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1962" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1962" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1997" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1997" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0120">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0120</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:09.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:892" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:892" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:886" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:886" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:885" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:885" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/150236" xml:lang="en">VU#150236</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" xml:lang="en">TA04-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp" xml:lang="en">MS04-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15712" xml:lang="en">ssl-message-dos(15712)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10115" xml:lang="en">10115</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-114.shtml" xml:lang="en">O-114</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:892" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:892" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:885" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:885" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:886" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:886" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0121">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:outlook:2002:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2002:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0121</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:35.587-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:843" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:843" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-070A.html" xml:lang="en">TA04-070A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/305206" xml:lang="en">VU#305206</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9827" xml:lang="en">9827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms04-009.asp" xml:lang="en">MS04-009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=79&amp;type=vulnerabilities" xml:lang="en">20040309 Microsoft Outlook "mailto:" Parameter Passing Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15429" xml:lang="en">outlook-ms04009-patch(15429)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15414" xml:lang="en">outlook-mailtourl-execute-code(15414)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-096.shtml" xml:lang="en">O-096</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107893704602842&amp;w=2" xml:lang="en">20040310 Outlook mailto: URL argument injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:843" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:843" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0122">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:msn_messenger:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:msn_messenger:6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:msn_messenger:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:msn_messenger:6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0122</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:35.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:844" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:844" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/688094" xml:lang="en">VU#688094</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9828" xml:lang="en">9828</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms04-010.asp" xml:lang="en">MS04-010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15427" xml:lang="en">msn-ms04010-patch(15427)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15415" xml:lang="en">msn-request-view-files(15415)</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:844" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:844" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0123">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0123</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:10.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:924" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:924" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1076" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1076" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1007" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1007" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/255924" xml:lang="en">VU#255924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" xml:lang="en">TA04-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15713" xml:lang="en">win-asn1-double-free(15713)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10118" xml:lang="en">10118</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp" xml:lang="en">MS04-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-114.shtml" xml:lang="en">O-114</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1076" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1076" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:924" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:924" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1007" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1007" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0124">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0124</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:10.133-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1072" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1072" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1066" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1066" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1062" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1062" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1041" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1041" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/212892" xml:lang="en">VU#212892</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" xml:lang="en">TA04-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15711" xml:lang="en">win-objectidentifier-open-port(15711)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10121" xml:lang="en">10121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms04-012.asp" xml:lang="en">MS04-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-115.shtml" xml:lang="en">O-115</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11065/" xml:lang="en">11065</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1072" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1072" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1062" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1062" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1066" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1066" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1041" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1041" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2004-0125">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.0:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1.1:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.2:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:release_p38"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4:release_p42"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:release_p32"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:release_p20"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:release_p17"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8:pre-release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8:release_p6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.9:pre-release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.9:releng"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.9:pre-release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:release_p17</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:release_p20</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:release_p38</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1.1:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4:release_p42</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1.1:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.9:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8:pre-release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.10</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.9</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8:release_p6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.0:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:release_p32</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.0:alpha</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.2:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:release</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0125</vuln:cve-id>
    <vuln:published-datetime>2004-08-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:36.227-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10485" xml:lang="en">10485</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/16342" xml:lang="en">freebsd-jailed-table-modify(16342)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:12.jailroute.asc" xml:lang="en">FreeBSD-SA-04:12</vuln:reference>
    </vuln:references>
    <vuln:summary>The jail system call in FreeBSD 4.x before 4.10-RELEASE does not verify that an attempt to manipulate routing tables originated from a non-jailed process, which could allow local users to modify the routing table.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0126">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2.1:release"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.2.1:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0126</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:36.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9762" xml:lang="en">9762</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:03.jail.asc" xml:lang="en">FreeBSD-SA-04:03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15344" xml:lang="en">freebsd-jailattach-gain-privileges(15344)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/4101" xml:lang="en">4101</vuln:reference>
    </vuln:references>
    <vuln:summary>The jail_attach system call in FreeBSD 5.1 and 5.2 changes the directory of a calling process even if the process doesn't have permission to change directory, which allows local users to gain read/write privileges to files and directories within another jail.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0127">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.52.3"/>
        <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.60"/>
        <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.61"/>
        <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.61.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.65"/>
        <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.65.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpgedview:phpgedview:2.65.1</vuln:product>
      <vuln:product>cpe:/a:phpgedview:phpgedview:2.61.1</vuln:product>
      <vuln:product>cpe:/a:phpgedview:phpgedview:2.61</vuln:product>
      <vuln:product>cpe:/a:phpgedview:phpgedview:2.52.3</vuln:product>
      <vuln:product>cpe:/a:phpgedview:phpgedview:2.60</vuln:product>
      <vuln:product>cpe:/a:phpgedview:phpgedview:2.65</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0127</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:36.633-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9529" xml:lang="en">9529</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/352355" xml:lang="en">20040129 PHP Code Injection Vulnerabilities in phpGedView 2.65.1 and prior</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15129" xml:lang="en">phpgedview-editconfig-directory-traversal(15129)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1008892" xml:lang="en">1008892</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/displayvuln.php?osvdb_id=3768" xml:lang="en">3768</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10753/" xml:lang="en">10753</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via .. (dot dot) sequences in the gedcom_config parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0128">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.52.3"/>
        <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.60"/>
        <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.61"/>
        <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.61.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.65"/>
        <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.65.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpgedview:phpgedview:2.65.1</vuln:product>
      <vuln:product>cpe:/a:phpgedview:phpgedview:2.61.1</vuln:product>
      <vuln:product>cpe:/a:phpgedview:phpgedview:2.61</vuln:product>
      <vuln:product>cpe:/a:phpgedview:phpgedview:2.52.3</vuln:product>
      <vuln:product>cpe:/a:phpgedview:phpgedview:2.60</vuln:product>
      <vuln:product>cpe:/a:phpgedview:phpgedview:2.65</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0128</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:36.787-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9531" xml:lang="en">9531</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/352355" xml:lang="en">20040129 PHP Code Injection Vulnerabilities in phpGedView 2.65.1 and prior</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14987" xml:lang="en">phpgedview-gedfilconf-file-include(14987)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3769" xml:lang="en">3769</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=141517" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=141517</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10753/" xml:lang="en">10753</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains a malicious theme.php script.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0129">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.2_pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.2_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.2_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.2_rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.5.5_pl1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.5.5_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.5.5_rc2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.2.4</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.2_pre1</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.1.1</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.5.4</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.5.5_rc2</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.0.2</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.5.0</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.1</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.5.5</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.0.1</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.2_rc1</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.5.5_pl1</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.4.0</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.0.5</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.5.2</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.0</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.5.5_rc1</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.3.2</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.2.5</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.0.4</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.0.3</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.5.1</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.2_rc3</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.2_rc2</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.1.2</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.3.1</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.2.3</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.2.2</vuln:product>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0129</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:36.960-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9564" xml:lang="en">9564</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582619125932&amp;w=2" xml:lang="en">20040203 Arbitrary File Disclosure Vulnerability in phpMyAdmin 2.5.5-pl1 and prior</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.phpmyadmin.net/home_page/relnotes.php?rel=0" xml:lang="en">http://www.phpmyadmin.net/home_page/relnotes.php?rel=0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/forum/forum.php?forum_id=350228" xml:lang="en">http://sourceforge.net/forum/forum.php?forum_id=350228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200402-05.xml" xml:lang="en">GLSA-200402-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15021" xml:lang="en">phpmyadmin-dotdot-directory-traversal(15021)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3800" xml:lang="en">3800</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10769" xml:lang="en">10769</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0130">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpgedview:phpgedview:2.65"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpgedview:phpgedview:2.65</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0130</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:37.177-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/unixfocus/5NP0M1PBPQ.html" xml:lang="en">http://www.securiteam.com/unixfocus/5NP0M1PBPQ.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15128" xml:lang="en">phpgedview-loginphp-path-disclosure(15128)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6886" xml:lang="en">6886</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.netvigilance.com/advisory0001" xml:lang="en">http://www.netvigilance.com/advisory0001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/alerts/2004/Jan/1008844.html" xml:lang="en">1008844</vuln:reference>
    </vuln:references>
    <vuln:summary>login.php in phpGedView 2.65 and earlier allows remote attackers to obtain sensitive information via an HTTP request to login.php that does not contain the required username or password parameters, which causes the information to be leaked in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0131">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:radius:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:radius:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0131</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:12.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/277396" xml:lang="en">VU#277396</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15046" xml:lang="en">radius-radprintrequest-dos(15046)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9578" xml:lang="en">9578</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://ftp.gnu.org/gnu/radius/radius-1.2.tar.gz" xml:lang="en">http://ftp.gnu.org/gnu/radius/radius-1.2.tar.gz</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3824" xml:lang="en">3824</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=71&amp;type=vulnerabilities&amp;flashstatus=true" xml:lang="en">20040204 GNU Radius Remote Denial of Service Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10799" xml:lang="en">10799</vuln:reference>
    </vuln:references>
    <vuln:summary>The rad_print_request function in logger.c for GNU Radius daemon (radiusd) before 1.2 allows remote atackers to cause a denial of service (crash) via a UDP packet with an Acct-Status-Type attribute without a value and no Acct-Session-Id attribute, which causes a null dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0132">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.40"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.41"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.42"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.43"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.44"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.45"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:1.45b"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:2.0_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:2.0_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:visualshapers:ezcontents:2.0_rc3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:visualshapers:ezcontents:2.0.2</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:2.0.1</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:1.43</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:1.44</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:1.40</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:2.0_rc2</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:2.0_rc1</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:1.45b</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:1.42</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:1.41</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:2.0_rc3</vuln:product>
      <vuln:product>cpe:/a:visualshapers:ezcontents:1.45</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0132</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:12.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107651585921958&amp;w=2" xml:lang="en">20040210 PHP Code Injection Vulnerabilities in ezContents 2.0.2 and prior</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15135" xml:lang="en">ezcontents-multiple-file-include(15135)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[language_home] parameter to archivednews.php, and a malicious version of lang_admin.php.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0133">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0133</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:12.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html" xml:lang="en">ESA-20040428-004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213675028441&amp;w=2" xml:lang="en">2004-0020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040405-01-U.asc" xml:lang="en">20040405-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200407-02.xml" xml:lang="en">GLSA-200407-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15901" xml:lang="en">linux-xfs-info-disclosure(15901)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10151" xml:lang="en">10151</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029" xml:lang="en">MDKSA-2004:029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11362" xml:lang="en">11362</vuln:reference>
    </vuln:references>
    <vuln:summary>The XFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the XFS file system, which allows local users to obtain sensitive information by reading the raw device.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0134">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.1t"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.4b"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.4t"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5_iop"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5_ipr"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5a"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5b"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5e"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5g"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5h"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3::xfs"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1::xfs"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.22"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.22m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.23"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.24"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5_20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2004-0134</vuln:cve-id>
    <vuln:published-datetime>2004-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:37.803-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/16259" xml:lang="en">irix-cpr-gain-privileges(16259)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10418" xml:lang="en">10418</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040507-01-P.asc" xml:lang="en">20040507-01-P</vuln:reference>
    </vuln:references>
    <vuln:summary>cpr (libcpr) in SGI IRIX before 6.5.25 allows local users to gain privileges by loading a user provided library while restarting the checkpointed process.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0135">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.1t"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.4b"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.4t"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5_iop"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5_ipr"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5a"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5b"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5e"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5g"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5h"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3::xfs"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1::xfs"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.10m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.11m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.12m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.13m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.14m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.15m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.16m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.17m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.18m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.19m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.22"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.22m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.23"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.24"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.2m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.3m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.4m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.5m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.6m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.7m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.8m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.9m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5_20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5.4m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5a</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5_iop</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.23</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:3.3.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.4t</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:3.3.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:3.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.24</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:3.3.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5h</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:3.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.16m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.11m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.15</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.17m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.22m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0.1::xfs</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.9m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3::xfs</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.12m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5_20</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5g</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.1t</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5b</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.10m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.22</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5e</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.4f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.8m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.4b</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.18</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.2m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.14m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.19</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.3m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.13f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.7m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.5m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5_ipr</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0135</vuln:cve-id>
    <vuln:published-datetime>2004-08-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:13.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/16413" xml:lang="en">irix-sgiioprobe-gain-privileges(16413)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc" xml:lang="en">20040601-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/7122" xml:lang="en">7122</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11872" xml:lang="en">11872</vuln:reference>
    </vuln:references>
    <vuln:summary>The syssgi SGI_IOPROBE system call in IRIX 6.5.20 through 6.5.24 allows local users to gain privileges by reading and writing to kernel memory.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0136">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.22"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.23"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.24"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5.25</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.23</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.24</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.22</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20f</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0136</vuln:cve-id>
    <vuln:published-datetime>2004-08-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:13.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/16416" xml:lang="en">irix-mapelf32exec-dos(16416)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10547" xml:lang="en">10547</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc" xml:lang="en">20040601-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/7123" xml:lang="en">7123</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11872" xml:lang="en">11872</vuln:reference>
    </vuln:references>
    <vuln:summary>The mapelf32exec function call in IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system crash) via a "corrupted binary."</vuln:summary>
  </entry>
  <entry id="CVE-2004-0137">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.20m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.21m"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.22"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.23"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.24"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5.25</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.23</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.24</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.22</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21m</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.21f</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.20f</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0137</vuln:cve-id>
    <vuln:published-datetime>2004-08-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:38.740-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/16417" xml:lang="en">irix-page-dos(16417)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10549" xml:lang="en">10549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc" xml:lang="en">20040601-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/7124" xml:lang="en">7124</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11872" xml:lang="en">11872</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in init for IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system panic) as a result of "page invalidation issues."</vuln:summary>
  </entry>
  <entry id="CVE-2004-0138">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0138</vuln:cve-id>
    <vuln:published-datetime>2004-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:38.050-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-05-31T15:28:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10123" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10123" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1082" xml:lang="en">DSA-1082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1070" xml:lang="en">DSA-1070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1069" xml:lang="en">DSA-1069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1067" xml:lang="en">DSA-1067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20202" xml:lang="en">20202</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20163" xml:lang="en">20163</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20162" xml:lang="en">20162</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://linux.bkbits.net:8080/linux-2.4/cset@4021346f79nBb-4X_usRikR3Iyb4Vg" xml:lang="en">http://linux.bkbits.net:8080/linux-2.4/cset@4021346f79nBb-4X_usRikR3Iyb4Vg</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://kernel.debian.net/debian/pool/main/kernel-source-2.4.17/kernel-source-2.4.17_2.4.17-1woody4_ia64.changes" xml:lang="en">http://kernel.debian.net/debian/pool/main/kernel-source-2.4.17/kernel-source-2.4.17_2.4.17-1woody4_ia64.changes</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/43124" xml:lang="en">linux-kernel-elfloader-dos(43124)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/18174" xml:lang="en">18174</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-549.html" xml:lang="en">RHSA-2004:549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-504.html" xml:lang="en">RHSA-2004:504</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20338" xml:lang="en">20338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.25" xml:lang="en">http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.25</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10123" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10123" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The ELF loader in Linux kernel 2.4 before 2.4.25 allows local users to cause a denial of service (crash) via a crafted ELF file with an interpreter with an invalid arch (architecture), which triggers a BUG() when an invalid VMA is unmapped.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0139">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.22"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.23"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.24"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5.25</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.23</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.24</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.22</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0139</vuln:cve-id>
    <vuln:published-datetime>2005-01-10T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:39.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11276" xml:lang="en">11276</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/17547" xml:lang="en">irix-bsda-kernel(17547)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/12682" xml:lang="en">12682</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040905-01-P.asc" xml:lang="en">20040905-01-P</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the bsd.a kernel networking for SGI IRIX 6.5.22 through 6.5.25, and possibly earlier versions, in which "t_unbind changes t_bind's behavior," has unknown impact and attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0143">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:nokia:6310i"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nokia:6310i</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0143</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:39.287-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15107" xml:lang="en">nokia-obex-dos(15107)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9603" xml:lang="en">9603</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.pentest.co.uk/documents/ptl-2004-01.html" xml:lang="en">http://www.pentest.co.uk/documents/ptl-2004-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634788029065&amp;w=2" xml:lang="en">20040209 ptl-2004-01: Multiple vulnerabilities in Nokia phones</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0034.html" xml:lang="en">20040209 ptl-2004-01: Multiple vulnerabilities in Nokia phones</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple vulnerabilities in Nokia 6310(i) Mobile phones allow remote attackers to cause a denial of service (reset) via malformed Bluetooth OBject EXchange (OBEX) messages, probably triggering buffer overflows.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0148">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18::academ"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr10"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr11"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr12"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr13"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr14"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr15"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr4"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr5"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr6"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr7"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr8"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr9"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta2::academ"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_vr16"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_vr17"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_vr16</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr15</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_vr17</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr12</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta2::academ</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr14</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr9</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr7</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.1</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.5.0</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18::academ</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr10</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr13</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr4</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr5</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.4</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.6.2</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.6.1</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.6.0</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr8</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:2.3</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr11</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0148</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:39.460-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:648" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:648" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1637" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1637" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1636" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1636" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1147" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1147" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9832" xml:lang="en">9832</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-096.html" xml:lang="en">RHSA-2004:096</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-457" xml:lang="en">DSA-457</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15423" xml:lang="en">wuftpd-restrictedgid-gain-access(15423)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FRSIRT</vuln:source>
      <vuln:reference href="http://www.frsirt.com/english/advisories/2006/1867" xml:lang="en">ADV-2006-1867</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102356-1" xml:lang="en">102356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20168" xml:lang="en">20168</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11055" xml:lang="en">11055</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108999466902690&amp;w=2" xml:lang="en">SSRT4704</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1637" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1637" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1147" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1147" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:648" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:648" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1636" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1636" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0149">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xboing:xboing:2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xboing:xboing:2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0149</vuln:cve-id>
    <vuln:published-datetime>2004-05-04T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:39.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-451" xml:lang="en">DSA-451</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15347" xml:lang="en">xboing-bo(15347)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9764" xml:lang="en">9764</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in xboing before 2.4 allow local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0150">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:python_software_foundation:python:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:python_software_foundation:python:2.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:python_software_foundation:python:2.2</vuln:product>
      <vuln:product>cpe:/a:python_software_foundation:python:2.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0150</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:16.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9836" xml:lang="en">9836</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-458" xml:lang="en">DSA-458</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15409" xml:lang="en">python-getaddrinfo-bo(15409)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/4172" xml:lang="en">4172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:019" xml:lang="en">MDKSA-2004:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200409-03.xml" xml:lang="en">GLSA-200409-03</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the getaddrinfo function in Python 2.2 before 2.2.2, when IPv6 support is disabled, allows remote attackers to execute arbitrary code via an IPv6 address that is obtained using DNS.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0151">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xintercepttalk:xitalk:1.1.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xintercepttalk:xitalk:1.1.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0151</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:39.960-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15456" xml:lang="en">xitalk-gain-privileges(15456)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9851" xml:lang="en">9851</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-462" xml:lang="en">DSA-462</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://shellcode.org/Advisories/XITALK.txt" xml:lang="en">http://shellcode.org/Advisories/XITALK.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11114/" xml:lang="en">11114</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in xitalk 1.1.11 and earlier allows local users to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0152">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:emil:emil:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:emil:emil:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:emil:emil:2.1.0_beta9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:emil:emil:2.1.0_beta9</vuln:product>
      <vuln:product>cpe:/a:emil:emil:2.0.5</vuln:product>
      <vuln:product>cpe:/a:emil:emil:2.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0152</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:40.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-468" xml:lang="en">DSA-468</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15601" xml:lang="en">emil-email-bo(15601)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108024939827236&amp;w=2" xml:lang="en">20040325 Re: [SECURITY] [DSA 468-1] New emil packages fix multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple stack-based buffer overflows in (1) the encode_mime function, (2) the encode_uuencode function, (3) or the decode_uuencode function for emil 2.1.0 and earlier allow remote attackers to execute arbitrary code via e-mail messages containing attachments with filenames.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0153">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:emil:emil:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:emil:emil:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:emil:emil:2.1.0_beta9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:emil:emil:2.1.0_beta9</vuln:product>
      <vuln:product>cpe:/a:emil:emil:2.0.5</vuln:product>
      <vuln:product>cpe:/a:emil:emil:2.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0153</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:40.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-468" xml:lang="en">DSA-468</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15602" xml:lang="en">emil-format-string(15602)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108024939827236&amp;w=2" xml:lang="en">20040325 Re: [SECURITY] [DSA 468-1] New emil packages fix multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple format string vulnerabilities in emil 2.1.0 and earlier may allow remote attackers to execute arbitrary code by triggering certain error messages.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0154">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nfs:nfs-utils:1.0.3</vuln:product>
      <vuln:product>cpe:/a:nfs:nfs-utils:1.0.6</vuln:product>
      <vuln:product>cpe:/a:nfs:nfs-utils:1.0.1</vuln:product>
      <vuln:product>cpe:/a:nfs:nfs-utils:1.0</vuln:product>
      <vuln:product>cpe:/a:nfs:nfs-utils:1.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0154</vuln:cve-id>
    <vuln:published-datetime>2004-06-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:39.017-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9673" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9673" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:861" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:861" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15418" xml:lang="en">nfs-utils-dns-dos(15418)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/misc/2004/TSL-2004-0009-nfs-utils.asc.txt" xml:lang="en">2004-0009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9813" xml:lang="en">9813</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-072.html" xml:lang="en">RHSA-2004:072</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugzilla.redhat.com/bugzilla/long_list.cgi?buglist=114535" xml:lang="en">http://bugzilla.redhat.com/bugzilla/long_list.cgi?buglist=114535</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:861" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:861" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9673" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9673" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0155">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:kame:racoon"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kame:racoon</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0155</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:39.160-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9291" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9291" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:945" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:945" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/552398" xml:lang="en">VU#552398</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-165.html" xml:lang="en">RHSA-2004:165</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2" xml:lang="en">APPLE-SA-2004-05-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108136746911000&amp;w=2" xml:lang="en">20040407 CAN-2004-0155:  The KAME IKE Daemon Racoon does not verify RSA Signatures during Phase 1, allows man-in-the-middle attacks and unauthorized connections</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10072" xml:lang="en">10072</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:069" xml:lang="en">MDKSA-2004:069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200406-17.xml" xml:lang="en">GLSA-200406-17</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11328" xml:lang="en">11328</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt" xml:lang="en">SCOSA-2005.10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:027" xml:lang="en">MDKSA-2004:027</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9291" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9291" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:945" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:945" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middle attacks using a valid, trusted X.509 certificate.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0156">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ssmtp:ssmtp:2.49"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ssmtp:ssmtp:2.49</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0156</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:17.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-485" xml:lang="en">DSA-485</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200404-18.xml" xml:lang="en">GLSA-200404-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15872" xml:lang="en">ssmtp-die-logevent-format-string(15872)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10150" xml:lang="en">10150</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/5361" xml:lang="en">5361</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/5360" xml:lang="en">5360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1009788" xml:lang="en">1009788</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11571" xml:lang="en">11571</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11485" xml:lang="en">11485</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11384" xml:lang="en">11384</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11378" xml:lang="en">11378</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403772130855&amp;w=2" xml:lang="en">20040507 [OpenPKG-SA-2004.020] OpenPKG Security Advisory (ssmtp)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerabilities in the (1) die or (2) log_event functions for ssmtp before 2.50.6 allow remote mail relays to cause a denial of service and possibly execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0157">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xonix:xonix:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xonix:xonix:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0157</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:40.880-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-484" xml:lang="en">DSA-484</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15873" xml:lang="en">xonix-privilege-dropping(15873)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10149" xml:lang="en">10149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/5358" xml:lang="en">5358</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://shellcode.org/Advisories/XONIX.txt" xml:lang="en">http://shellcode.org/Advisories/XONIX.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1009789" xml:lang="en">1009789</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11382" xml:lang="en">11382</vuln:reference>
    </vuln:references>
    <vuln:summary>x11.c in xonix 1.4 and earlier uses the current working directory to find and execute the rmail program, which allows local users to execute arbitrary code by modifying the path to point to a malicious rmail program.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0158">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:lgames:lbreakout2:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:lgames:lbreakout2:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:lgames:lbreakout2:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:lgames:lbreakout2:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:lgames:lbreakout2:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:lgames:lbreakout2:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:lgames:lbreakout2:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:lgames:lbreakout2:2.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lgames:lbreakout2:2.2.2</vuln:product>
      <vuln:product>cpe:/a:lgames:lbreakout2:2.1.1</vuln:product>
      <vuln:product>cpe:/a:lgames:lbreakout2:2.2.1</vuln:product>
      <vuln:product>cpe:/a:lgames:lbreakout2:2.2</vuln:product>
      <vuln:product>cpe:/a:lgames:lbreakout2:2.1</vuln:product>
      <vuln:product>cpe:/a:lgames:lbreakout2:2.1.2</vuln:product>
      <vuln:product>cpe:/a:lgames:lbreakout2:2.0.1</vuln:product>
      <vuln:product>cpe:/a:lgames:lbreakout2:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0158</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:41.053-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15229" xml:lang="en">breakout2-home-bo(15229)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9712" xml:lang="en">9712</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-445" xml:lang="en">DSA-445</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://security.debian.org/pool/updates/main/l/lbreakout2/lbreakout2_2.2.2-1woody1.diff.gz" xml:lang="en">http://security.debian.org/pool/updates/main/l/lbreakout2/lbreakout2_2.2.2-1woody1.diff.gz</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755821705356&amp;w=2" xml:lang="en">20040222 lbreakout2 &lt; 2.4beta-2 local exploit</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in lbreakout2 allows local users to gain 'games' group privileges via a large HOME environment variable to (1) editor.c, (2) theme.c, (3) manager.c, (4) config.c, (5) game.c, (6) levels.c, or (7) main.c.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0159">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:samhain_labs:hsftp:1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samhain_labs:hsftp:1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:samhain_labs:hsftp:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samhain_labs:hsftp:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samhain_labs:hsftp:1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samhain_labs:hsftp:1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samhain_labs:hsftp:1.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:samhain_labs:hsftp:1.7</vuln:product>
      <vuln:product>cpe:/a:samhain_labs:hsftp:1.5</vuln:product>
      <vuln:product>cpe:/a:samhain_labs:hsftp:1.11</vuln:product>
      <vuln:product>cpe:/a:samhain_labs:hsftp:1.4</vuln:product>
      <vuln:product>cpe:/a:samhain_labs:hsftp:1.6</vuln:product>
      <vuln:product>cpe:/a:samhain_labs:hsftp:1.9</vuln:product>
      <vuln:product>cpe:/a:samhain_labs:hsftp:1.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0159</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:19.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9715" xml:lang="en">9715</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755803218677&amp;w=2" xml:lang="en">DSA-447</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15276" xml:lang="en">hsftp-format-string(15276)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/4029" xml:lang="en">4029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017737.html" xml:lang="en">20040223 Re: [SECURITY] [DSA 447-1] New hsftp packages fix format string vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via file names containing format string characters that are not properly handled when executing an "ls" command.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0160">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:synaesthesia:synaesthesia:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:synaesthesia:synaesthesia:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:synaesthesia:synaesthesia:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:synaesthesia:synaesthesia:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:synaesthesia:synaesthesia:2.1.0</vuln:product>
      <vuln:product>cpe:/a:synaesthesia:synaesthesia:2.2</vuln:product>
      <vuln:product>cpe:/a:synaesthesia:synaesthesia:2.1.2</vuln:product>
      <vuln:product>cpe:/a:synaesthesia:synaesthesia:2.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0160</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:41.367-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15279" xml:lang="en">synaesthesia-configuration-symlink-attack(15279)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9713" xml:lang="en">9713</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-446" xml:lang="en">DSA-446</vuln:reference>
    </vuln:references>
    <vuln:summary>Synaesthesia 2.2 and earlier allows local users to execute arbitrary code via a symlink attack on the configuration file.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0161">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.31"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.32"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.2</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.3</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.10</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.8</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.31</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.32</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.6</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.2</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.14</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.0</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.5</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.1</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.7</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.3</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.11</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.3</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.15</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.7</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.0</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.13</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.4</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0161</vuln:cve-id>
    <vuln:published-datetime>2004-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:20.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/9274" xml:lang="en">mime-tools-parameter-encoding(9274)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" xml:lang="en">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109524928232568&amp;w=2" xml:lang="en">20040914 Corsaire Security Advisory - Multiple vendor MIME RFC2231 encoding issue</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use RFC2231 encoding, which may be interpreted differently by mail clients.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0162">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:clearswift:mailsweeper:4.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.31"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.32"/>
        <cpe-lang:fact-ref name="cpe:/a:f-secure:internet_gatekeeper:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:paul_l_daniels:ripmime:1.3.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.2</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.3</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.10</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.8</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.31</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.32</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.6</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.2</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.14</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.0</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.5</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.1</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.7</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.3</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.11</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.3</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.15</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.7</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.3.2.0</vuln:product>
      <vuln:product>cpe:/a:clearswift:mailsweeper:4.3.13</vuln:product>
      <vuln:product>cpe:/a:f-secure:internet_gatekeeper:6.4</vuln:product>
      <vuln:product>cpe:/a:paul_l_daniels:ripmime:1.2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0162</vuln:cve-id>
    <vuln:published-datetime>2004-10-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:20.397-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/17332" xml:lang="en">mime-rfc822-filtering-bypass(17332)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" xml:lang="en">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109517563513776&amp;w=2" xml:lang="en">20040914 Corsaire Security Advisory - Multiple vendor MIME RFC822 comment issue</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME encapsulation that uses RFC822 comment fields, which may be interpreted as other fields by mail clients.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0163">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sygate_technologies:secure_enterprise:3.5mr3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sygate_technologies:secure_enterprise:3.5mr3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0163</vuln:cve-id>
    <vuln:published-datetime>2004-09-28T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:41.943-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/16945" xml:lang="en">sse-replay-dos(16945)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.corsaire.com/advisories/c031120-002.txt" xml:lang="en">http://www.corsaire.com/advisories/c031120-002.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109215685731675&amp;w=2" xml:lang="en">20040810 Corsaire Security Advisory - Sygate Secure Enterprise replay issue</vuln:reference>
    </vuln:references>
    <vuln:summary>Sygate Secure Enterprise (SSE) 3.5MR3 and earlier does not change the key used to encrypt data, which allows remote attackers to cause a denial of service (resource exhaustion) by capturing a session and repeatedly replaying the session.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0164">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:kame:racoon:all_versions"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kame:racoon:all_versions</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0164</vuln:cve-id>
    <vuln:published-datetime>2004-03-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:39.957-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9737" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9737" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:947" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:947" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411758202662&amp;w=2" xml:lang="en">20040114 Re: unauthorized deletion of IPsec (and ISAKMP) SAs in racoon</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14118" xml:lang="en">openbsd-isakmp-initialcontact-delete-sa(14118)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14117" xml:lang="en">openbsd-isakmp-invalidspi-delete-sa(14117)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9417" xml:lang="en">9417</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" xml:lang="en">APPLE-SA-2004-02-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-001.txt.asc" xml:lang="en">NetBSD-SA2004-001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9416" xml:lang="en">9416</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107403331309838&amp;w=2" xml:lang="en">20040113 unauthorized deletion of IPsec (and ISAKMP) SAs in racoon</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:947" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:947" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9737" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9737" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0165">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0165</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:20.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/841742" xml:lang="en">VU#841742</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9730" xml:lang="en">9730</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ATSTAKE</vuln:source>
      <vuln:reference href="http://www.atstake.com/research/advisories/2004/a022304-1.txt" xml:lang="en">A022304-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15297" xml:lang="en">macos-pppd-format-string(15297)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6822" xml:lang="en">6822</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" xml:lang="en">APPLE-SA-2004-02-23</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2 and earlier allows remote attackers to read arbitrary pppd process data, including PAP or CHAP authentication credentials, to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0166">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0166</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:15:12.703-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/194238" xml:lang="en">VU#194238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/14993" xml:lang="en">macosx-safari-unknown(14993)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10959" xml:lang="en">10959</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" xml:lang="en">APPLE-SA-2004-02-23</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to "the display of URLs in the status bar."</vuln:summary>
  </entry>
  <entry id="CVE-2004-0167">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0167</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:15:12.797-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/578886" xml:lang="en">VU#578886</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15300" xml:lang="en">macos-diskarbitration-unknown(15300)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9731" xml:lang="en">9731</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6824" xml:lang="en">6824</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10959" xml:lang="en">10959</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" xml:lang="en">APPLE-SA-2004-02-23</vuln:reference>
    </vuln:references>
    <vuln:summary>DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0168">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0168</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:15:12.860-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15299" xml:lang="en">macos-corefoundation-unknown(15299)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" xml:lang="en">APPLE-SA-2004-02-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10959/" xml:lang="en">10959</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging."</vuln:summary>
  </entry>
  <entry id="CVE-2004-0169">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0169</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:20.897-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/460350" xml:lang="en">VU#460350</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9735" xml:lang="en">9735</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15291" xml:lang="en">darwin-describe-request-dos(15291)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6837" xml:lang="en">6837</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6826" xml:lang="en">6826</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=75&amp;type=vulnerabilities" xml:lang="en">20040223 Darwin Streaming Server Remote Denial of Service Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" xml:lang="en">APPLE-SA-2004-02-23</vuln:reference>
    </vuln:references>
    <vuln:summary>QuickTime Streaming Server in MacOS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (crash) via DESCRIBE requests with long User-Agent fields, which causes an Assert error to be triggered in the BufferIsFull function.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0171">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.4</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.9</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0171</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:43.100-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/395670" xml:lang="en">VU#395670</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9792" xml:lang="en">9792</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=78&amp;type=vulnerabilities" xml:lang="en">20040302 FreeBSD Memory Buffer Exhaustion Denial of Service Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15369" xml:lang="en">freebsd-mbuf-dos(15369)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/4124" xml:lang="en">4124</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.seifried.org/pipermail/security/2004-May/003743.html" xml:lang="en">APPLE-SA-2004-05-28</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:04.tcp.asc" xml:lang="en">FreeBSD-SA-04:04</vuln:reference>
    </vuln:references>
    <vuln:summary>FreeBSD 5.1 and earlier, and Mac OS X before 10.3.4, allows remote attackers to cause a denial of service (resource exhaustion of memory buffers and system crash) via a large number of out-of-sequence TCP packets, which prevents the operating system from creating new connections.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0172">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:juan_cespedes:ltrace:0.3.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:juan_cespedes:ltrace:0.3.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0172</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:21.430-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/13389" xml:lang="en">ltrace-searchforcommand-bo(13389)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8790" xml:lang="en">8790</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1007896" xml:lang="en">1007896</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011610.html" xml:lang="en">20031008 ltrace bug</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011600.html" xml:lang="en">20031008 ltrace bug</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in the search_for_command function of ltrace 0.3.10, if it is installed setuid, could allow local users to execute arbitrary code via a long filename.  NOTE: It is unclear whether there are any packages that install ltrace as a setuid program, so this candidate might be REJECTed.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0173">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:0.8.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:0.8.14"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:1.2.5</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.0</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.0.5</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:0.8.11</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.1</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.1.1</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.0.2</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:0.8.14</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.2</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0173</vuln:cve-id>
    <vuln:published-datetime>2004-04-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:21.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15293" xml:lang="en">apache-cygwin-directory-traversal(15293)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9733" xml:lang="en">9733</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.apacheweek.com/issues/04-03-12" xml:lang="en">http://www.apacheweek.com/issues/04-03-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10962" xml:lang="en">10962</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107765545431387&amp;w=2" xml:lang="en">20040224 STG Security Advisory: [SSA-20040217-06] Apache for cygwin</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017740.html" xml:lang="en">20040224 STG Security Advisory: [SSA-20040217-06] Apache for cygwin directory traversal vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://issues.apache.org/bugzilla/show_bug.cgi?id=26152" xml:lang="en">http://issues.apache.org/bugzilla/show_bug.cgi?id=26152</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0174">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.49"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:2.0.49</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0174</vuln:cve-id>
    <vuln:published-datetime>2004-05-04T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:21.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1982" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1982" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:100110" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100110" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/132110" xml:lang="en">VU#132110</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15540" xml:lang="en">apache-socket-starvation-dos(15540)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-405.html" xml:lang="en">RHSA-2004:405</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108066914830552&amp;w=2" xml:lang="en">2004-0017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107973894328806&amp;w=2" xml:lang="en">20040319 [ANNOUNCE] Apache HTTP Server 2.0.49 Released (fwd)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2004/0027" xml:lang="en">2004-0027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200405-22.xml" xml:lang="en">GLSA-200405-22</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11170" xml:lang="en">11170</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.529643" xml:lang="en">SSA:2004-133</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/alerts/2004/Mar/1009495.html" xml:lang="en">1009495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9921" xml:lang="en">9921</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:046" xml:lang="en">MDKSA-2004:046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.apache.org/dist/httpd/CHANGES_1.3" xml:lang="en">http://www.apache.org/dist/httpd/CHANGES_1.3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1" xml:lang="en">57628</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1" xml:lang="en">101555</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108731648532365&amp;w=2" xml:lang="en">SSRT4717</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108437852004207&amp;w=2" xml:lang="en">20040512 [OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2" xml:lang="en">APPLE-SA-2004-05-03</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1982" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1982" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:100110" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:100110" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."</vuln:summary>
  </entry>
  <entry id="CVE-2004-0175">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.0.1p1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.0.2p1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.0p1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.1p1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.2.2p1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.2.3p1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.3p1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:openbsd:openssh:3.4p1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openbsd:openssh:3.3</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:3.0p1</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:3.1p1</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:3.0.2</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:3.0.1</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:3.0</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:3.1</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:3.4</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:3.2.2p1</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:3.2.3p1</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:3.2</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:3.3p1</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:3.0.2p1</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:3.4p1</vuln:product>
      <vuln:product>cpe:/a:openbsd:openssh:3.0.1p1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0175</vuln:cve-id>
    <vuln:published-datetime>2004-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:15:13.330-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10184" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10184" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9986" xml:lang="en">9986</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=120147" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=120147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/16323" xml:lang="en">openssh-scp-file-overwrite(16323)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-567.html" xml:lang="en">RHSA-2005:567</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-562.html" xml:lang="en">RHSA-2005:562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-495.html" xml:lang="en">RHSA-2005:495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-481.html" xml:lang="en">RHSA-2005:481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-165.html" xml:lang="en">RHSA-2005:165</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-106.html" xml:lang="en">RHSA-2005:106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-074.html" xml:lang="en">RHSA-2005:074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/9550" xml:lang="en">9550</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2004_09_kernel.html" xml:lang="en">SuSE-SA:2004:009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:191" xml:lang="en">MDVSA-2008:191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:100" xml:lang="en">MDKSA-2005:100</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.juniper.net/support/security/alerts/adv59739.txt" xml:lang="en">http://www.juniper.net/support/security/alerts/adv59739.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-212.shtml" xml:lang="en">O-212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19243" xml:lang="en">19243</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/17135" xml:lang="en">17135</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000831" xml:lang="en">CLSA-2004:831</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.11/SCOSA-2006.11.txt" xml:lang="en">SCOSA-2006.11</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10184" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10184" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files.  NOTE: this may be a rediscovery of CVE-2000-0992.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0176">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.8.13"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.8.14"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.8.18"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.8.19"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.11"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.12"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.13"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.14"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.15"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.16"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.8</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.7</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.11</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.16</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.2</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.9</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.14</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.4</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.10</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.5</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.8.14</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.13</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.1</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.2</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.8.18</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.12</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.8.13</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.15</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.3</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.1</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.8.19</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.6</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0176</vuln:cve-id>
    <vuln:published-datetime>2004-05-04T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:41.207-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10187" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10187" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:887" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:887" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:878" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:878" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/931588" xml:lang="en">VU#931588</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/864884" xml:lang="en">VU#864884</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/740188" xml:lang="en">VU#740188</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/659140" xml:lang="en">VU#659140</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/644886" xml:lang="en">VU#644886</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/591820" xml:lang="en">VU#591820</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/433596" xml:lang="en">VU#433596</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/125156" xml:lang="en">VU#125156</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/119876" xml:lang="en">VU#119876</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-511" xml:lang="en">DSA-511</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108058005324316&amp;w=2" xml:lang="en">20040329 LNSA-#2004-0007: Multiple security problems in Ethereal</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15569" xml:lang="en">ethereal-multiple-dissectors-bo(15569)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-137.html" xml:lang="en">RHSA-2004:137</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-136.html" xml:lang="en">RHSA-2004:136</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00013.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00013.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200403-07.xml" xml:lang="en">GLSA-200403-07</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security.e-matters.de/advisories/032004.html" xml:lang="en">http://security.e-matters.de/advisories/032004.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11185" xml:lang="en">11185</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108007072215742&amp;w=2" xml:lang="en">20040323 Advisory 03/2004: Multiple (13) Ethereal remote overflows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6893" xml:lang="en">6893</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:024" xml:lang="en">MDKSA-2004:024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213710306260&amp;w=2" xml:lang="en">20040416 [OpenPKG-SA-2004.015] OpenPKG Security Advisory (ethereal)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000835" xml:lang="en">CLA-2004:835</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:878" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:878" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10187" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10187" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:887" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:887" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0177">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0177</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:41.347-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10556" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10556" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html" xml:lang="en">ESA-20040428-004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-495" xml:lang="en">DSA-495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2004-166.html" xml:lang="en">RHSA-2004:166</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213675028441&amp;w=2" xml:lang="en">2004-0020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://bugzilla.fedora.us/show_bug.cgi?id=2336" xml:lang="en">FLSA:2336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-491" xml:lang="en">DSA-491</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-489" xml:lang="en">DSA-489</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-482" xml:lang="en">DSA-482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-481" xml:lang="en">DSA-481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-480" xml:lang="en">DSA-480</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-479" xml:lang="en">DSA-479</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200407-02.xml" xml:lang="en">GLSA-200407-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://linux.bkbits.net:8080/linux-2.4/cset@4056b368s6vpJbGWxDD_LhQNYQrdzQ" xml:lang="en">http://linux.bkbits.net:8080/linux-2.4/cset@4056b368s6vpJbGWxDD_LhQNYQrdzQ</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15867" xml:lang="en">linux-ext3-info-disclosure(15867)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10152" xml:lang="en">10152</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-293.html" xml:lang="en">RHSA-2005:293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-505.html" xml:lang="en">RHSA-2004:505</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-504.html" xml:lang="en">RHSA-2004:504</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029" xml:lang="en">MDKSA-2004:029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-127.shtml" xml:lang="en">O-127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-126.shtml" xml:lang="en">O-126</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-121.shtml" xml:lang="en">O-121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846" xml:lang="en">CLA-2004:846</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10556" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10556" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The ext3 code in Linux 2.4.x before 2.4.26 does not properly initialize journal descriptor blocks, which causes an information leak in which in-memory data is written to the device for the ext3 file system, which allows privileged users to obtain portions of kernel memory by reading the raw device.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0178">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0178</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:41.470-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9427" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9427" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-495" xml:lang="en">DSA-495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-491" xml:lang="en">DSA-491</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-489" xml:lang="en">DSA-489</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-482" xml:lang="en">DSA-482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-437.html" xml:lang="en">RHSA-2004:437</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-413.html" xml:lang="en">RHSA-2004:413</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-481" xml:lang="en">DSA-481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-480" xml:lang="en">DSA-480</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-479" xml:lang="en">DSA-479</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200407-02.xml" xml:lang="en">GLSA-200407-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://linux.bkbits.net:8080/linux-2.4/cset@404ce5967rY2Ryu6Z_uNbYh643wuFA" xml:lang="en">http://linux.bkbits.net:8080/linux-2.4/cset@404ce5967rY2Ryu6Z_uNbYh643wuFA</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040804-01-U.asc" xml:lang="en">20040804-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15868" xml:lang="en">linux-sound-blaster-dos(15868)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9985" xml:lang="en">9985</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029" xml:lang="en">MDKSA-2004:029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-193.shtml" xml:lang="en">O-193</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-127.shtml" xml:lang="en">O-127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-121.shtml" xml:lang="en">O-121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846" xml:lang="en">CLA-2004:846</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9427" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9427" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The OSS code for the Sound Blaster (sb16) driver in Linux 2.4.x before 2.4.26, when operating in 16 bit mode, does not properly handle certain sample sizes, which allows local users to cause a denial of service (crash) via a sample with an odd number of bytes.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0179">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cadaver:cadaver_webdav_client:0.20.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cadaver:cadaver_webdav_client:0.20.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cadaver:cadaver_webdav_client:0.20.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cadaver:cadaver_webdav_client:0.20.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cadaver:cadaver_webdav_client:0.20.4"/>
        <cpe-lang:fact-ref name="cpe:/a:cadaver:cadaver_webdav_client:0.20.5"/>
        <cpe-lang:fact-ref name="cpe:/a:cadaver:cadaver_webdav_client:0.21.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cadaver:cadaver_webdav_client:0.22.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cadaver:cadaver_webdav_client:0.22.1"/>
        <cpe-lang:fact-ref name="cpe:/a:neon:neon_client_library:0.19.3"/>
        <cpe-lang:fact-ref name="cpe:/a:neon:neon_client_library:0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:neon:neon_client_library:0.23.1"/>
        <cpe-lang:fact-ref name="cpe:/a:neon:neon_client_library:0.23.2"/>
        <cpe-lang:fact-ref name="cpe:/a:neon:neon_client_library:0.23.3"/>
        <cpe-lang:fact-ref name="cpe:/a:neon:neon_client_library:0.23.4"/>
        <cpe-lang:fact-ref name="cpe:/a:neon:neon_client_library:0.23.5"/>
        <cpe-lang:fact-ref name="cpe:/a:neon:neon_client_library:0.23.6"/>
        <cpe-lang:fact-ref name="cpe:/a:neon:neon_client_library:0.23.7"/>
        <cpe-lang:fact-ref name="cpe:/a:neon:neon_client_library:0.23.8"/>
        <cpe-lang:fact-ref name="cpe:/a:neon:neon_client_library:0.24"/>
        <cpe-lang:fact-ref name="cpe:/a:neon:neon_client_library:0.24.1"/>
        <cpe-lang:fact-ref name="cpe:/a:neon:neon_client_library:0.24.2"/>
        <cpe-lang:fact-ref name="cpe:/a:neon:neon_client_library:0.24.3"/>
        <cpe-lang:fact-ref name="cpe:/a:neon:neon_client_library:0.24.4"/>
        <cpe-lang:fact-ref name="cpe:/a:openoffice:openoffice:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:subversion:subversion"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cadaver:cadaver_webdav_client:0.20.2</vuln:product>
      <vuln:product>cpe:/a:neon:neon_client_library:0.24.4</vuln:product>
      <vuln:product>cpe:/a:cadaver:cadaver_webdav_client:0.20.4</vuln:product>
      <vuln:product>cpe:/a:neon:neon_client_library:0.23.5</vuln:product>
      <vuln:product>cpe:/a:cadaver:cadaver_webdav_client:0.20.0</vuln:product>
      <vuln:product>cpe:/a:cadaver:cadaver_webdav_client:0.22.1</vuln:product>
      <vuln:product>cpe:/a:neon:neon_client_library:0.23.2</vuln:product>
      <vuln:product>cpe:/a:subversion:subversion</vuln:product>
      <vuln:product>cpe:/a:neon:neon_client_library:0.23.1</vuln:product>
      <vuln:product>cpe:/a:neon:neon_client_library:0.23.3</vuln:product>
      <vuln:product>cpe:/a:neon:neon_client_library:0.23.6</vuln:product>
      <vuln:product>cpe:/a:neon:neon_client_library:0.24</vuln:product>
      <vuln:product>cpe:/a:neon:neon_client_library:0.24.3</vuln:product>
      <vuln:product>cpe:/a:neon:neon_client_library:0.24.1</vuln:product>
      <vuln:product>cpe:/a:cadaver:cadaver_webdav_client:0.22.0</vuln:product>
      <vuln:product>cpe:/a:neon:neon_client_library:0.23</vuln:product>
      <vuln:product>cpe:/a:cadaver:cadaver_webdav_client:0.20.1</vuln:product>
      <vuln:product>cpe:/a:openoffice:openoffice:1.1.2</vuln:product>
      <vuln:product>cpe:/a:neon:neon_client_library:0.23.8</vuln:product>
      <vuln:product>cpe:/a:cadaver:cadaver_webdav_client:0.21.0</vuln:product>
      <vuln:product>cpe:/a:neon:neon_client_library:0.19.3</vuln:product>
      <vuln:product>cpe:/a:neon:neon_client_library:0.24.2</vuln:product>
      <vuln:product>cpe:/a:neon:neon_client_library:0.23.4</vuln:product>
      <vuln:product>cpe:/a:cadaver:cadaver_webdav_client:0.20.5</vuln:product>
      <vuln:product>cpe:/a:cadaver:cadaver_webdav_client:0.20.3</vuln:product>
      <vuln:product>cpe:/a:neon:neon_client_library:0.23.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0179</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:41.817-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10913" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10913" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1065" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1065" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://bugzilla.fedora.us/show_bug.cgi?id=1552" xml:lang="en">FEDORA-2004-1552</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-160.html" xml:lang="en">RHSA-2004:160</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-159.html" xml:lang="en">RHSA-2004:159</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-158.html" xml:lang="en">RHSA-2004:158</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-157.html" xml:lang="en">RHSA-2004:157</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-487" xml:lang="en">DSA-487</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200405-04.xml" xml:lang="en">GLSA-200405-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200405-01.xml" xml:lang="en">GLSA-200405-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11363" xml:lang="en">11363</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2004-Apr/0003.html" xml:lang="en">SuSE-SA:2004:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2004-Apr/0002.html" xml:lang="en">SuSE-SA:2004:009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc" xml:lang="en">20040404-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10136" xml:lang="en">10136</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/5365" xml:lang="en">5365</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:032" xml:lang="en">MDKSA-2004:032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108214147022626&amp;w=2" xml:lang="en">20040416 void.at - neon format string bugs</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213873203477&amp;w=2" xml:lang="en">20040416 [OpenPKG-SA-2004.016] OpenPKG Security Advisory (neon)</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10913" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10913" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1065" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1065" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0180">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cvs:cvs:1.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cvs:cvs:1.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0180</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:41.940-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9462" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9462" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1042" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1042" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-154.html" xml:lang="en">RHSA-2004:154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-153.html" xml:lang="en">RHSA-2004:153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-486" xml:lang="en">DSA-486</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:07.cvs.asc" xml:lang="en">FreeBSD-SA-04:07</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc" xml:lang="en">20040404-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/002_cvs.patch" xml:lang="en">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/002_cvs.patch</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15864" xml:lang="en">cvs-rcs-create-files(15864)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.400181" xml:lang="en">SSA:2004-108-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:028" xml:lang="en">MDKSA-2004:028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200404-13.xml" xml:lang="en">GLSA-200404-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11548" xml:lang="en">11548</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11405" xml:lang="en">11405</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11400" xml:lang="en">11400</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11391" xml:lang="en">11391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11380" xml:lang="en">11380</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11377" xml:lang="en">11377</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11375" xml:lang="en">11375</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11374" xml:lang="en">11374</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11371" xml:lang="en">11371</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11368" xml:lang="en">11368</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108636445031613&amp;w=2" xml:lang="en">FEDORA-2004-1620</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1042" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1042" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9462" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9462" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute pathnames during checkouts or updates, a different vulnerability than CVE-2004-0405.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0181">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0181</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:15:13.767-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10329" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10329" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ENGARDE</vuln:source>
      <vuln:reference href="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html" xml:lang="en">ESA-20040428-004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213675028441&amp;w=2" xml:lang="en">2004-0020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2005/1878" xml:lang="en">ADV-2005-1878</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200407-02.xml" xml:lang="en">GLSA-200407-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15902" xml:lang="en">linux-jfs-info-disclosure(15902)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/2004/TLSA-2004-14.txt" xml:lang="en">TLSA-2004-14</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10143" xml:lang="en">10143</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-663.html" xml:lang="en">RHSA-2005:663</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-504.html" xml:lang="en">RHSA-2004:504</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029" xml:lang="en">MDKSA-2004:029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/17002" xml:lang="en">17002</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10329" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10329" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The JFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the JFS file system, which allows local users to obtain sensitive information by reading the raw device.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0182">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:mailman:2.0.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0182</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:44.927-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-156.html" xml:lang="en">RHSA-2004:156</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc" xml:lang="en">20040404-01-U</vuln:reference>
    </vuln:references>
    <vuln:summary>Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0183">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.8.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lbl:tcpdump:3.8.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0183</vuln:cve-id>
    <vuln:published-datetime>2004-05-04T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:42.393-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9971" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9971" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:972" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:972" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/240790" xml:lang="en">VU#240790</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-478" xml:lang="en">DSA-478</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://bugzilla.fedora.us/show_bug.cgi?id=1468" xml:lang="en">FEDORA-2004-1468</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15680" xml:lang="en">tcpdump-isakmp-delete-bo(15680)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.tcpdump.org/tcpdump-changes.txt" xml:lang="en">http://www.tcpdump.org/tcpdump-changes.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10003" xml:lang="en">10003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-219.html" xml:lang="en">RHSA-2004:219</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.rapid7.com/advisories/R7-0017.html" xml:lang="en">http://www.rapid7.com/advisories/R7-0017.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1009593" xml:lang="en">1009593</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11258" xml:lang="en">11258</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2004/0015" xml:lang="en">2004-0015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11320" xml:lang="en">11320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067265931525&amp;w=2" xml:lang="en">20040330 R7-0017: TCPDUMP ISAKMP payload handling denial-of-service vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:972" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:972" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9971" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9971" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0184">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:lbl:tcpdump:3.8.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lbl:tcpdump:3.8.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0184</vuln:cve-id>
    <vuln:published-datetime>2004-05-04T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:19:42.533-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9581" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9581" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:976" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:976" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/492558" xml:lang="en">VU#492558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-478" xml:lang="en">DSA-478</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://bugzilla.fedora.us/show_bug.cgi?id=1468" xml:lang="en">FEDORA-2004-1468</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15679" xml:lang="en">tcpdump-isakmp-integer-underflow(15679)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.tcpdump.org/tcpdump-changes.txt" xml:lang="en">http://www.tcpdump.org/tcpdump-changes.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10004" xml:lang="en">10004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-219.html" xml:lang="en">RHSA-2004:219</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.rapid7.com/advisories/R7-0017.html" xml:lang="en">http://www.rapid7.com/advisories/R7-0017.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1009593" xml:lang="en">1009593</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11258" xml:lang="en">11258</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067265931525&amp;w=2" xml:lang="en">20040330 R7-0017: TCPDUMP ISAKMP payload handling denial-of-service vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2004/0015" xml:lang="en">2004-0015</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9581" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9581" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:976" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:976" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0185">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.6.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0185</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:45.380-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/unixfocus/6X00Q1P8KC.html" xml:lang="en">http://www.securiteam.com/unixfocus/6X00Q1P8KC.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-096.html" xml:lang="en">RHSA-2004:096</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-457" xml:lang="en">DSA-457</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_2.6.2/skeychallenge.patch" xml:lang="en">ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_2.6.2/skeychallenge.patch</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/13518" xml:lang="en">wuftpd-skey-bo(13518)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://unixpunx.org/txt/exploits_archive/packetstorm/0310-advisories/wuftpd-skey.txt" xml:lang="en">http://unixpunx.org/txt/exploits_archive/packetstorm/0310-advisories/wuftpd-skey.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8893" xml:lang="en">8893</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the skey_challenge function in ftpd.c for wu-ftp daemon (wu-ftpd) 2.6.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a s/key (SKEY) request with a long name.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0186">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6_test9_cvs"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6_test9_cvs</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:2.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0186</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:45.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15131" xml:lang="en">samba-smbmnt-gain-privileges(15131)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9619" xml:lang="en">9619</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-463" xml:lang="en">DSA-463</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107636290906296&amp;w=2" xml:lang="en">20040209 Samba 3.x + kernel 2.6.x local root vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3916" xml:lang="en">3916</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107657505718743&amp;w=2" xml:lang="en">20040211 Re: Samba 3.x + kernel 2.6.x local root vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0187">
    <vuln:cve-id>CVE-2004-0187</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:27.837-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0185.  Reason: This candidate is a reservation duplicate of CVE-2004-0185.  Notes: All CVE users should reference CVE-2004-0185 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0188">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:calife:calife:2.8.4_c"/>
        <cpe-lang:fact-ref name="cpe:/a:calife:calife:2.8.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:calife:calife:2.8.4_c</vuln:product>
      <vuln:product>cpe:/a:calife:calife:2.8.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0188</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:45.820-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9756" xml:lang="en">9756</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-461" xml:lang="en">DSA-461</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15335" xml:lang="en">calife-long-password-bo(15335)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107789737832092&amp;w=2" xml:lang="en">20040227 Calife heap corrupt / potential local root exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9776" xml:lang="en">9776</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in Calife 2.8.5 and earlier may allow local users to execute arbitrary code via a long password.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0189">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.0_patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1_patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_stable7"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squid:squid:2.1_patch2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4_stable7</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3_stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.0_patch2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_stable4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0189</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:45.960-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:941" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:941" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:877" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:877" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/Advisories/SQUID-2004_1.txt" xml:lang="en">http://www.squid-cache.org/Advisories/SQUID-2004_1.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9778" xml:lang="en">9778</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15366" xml:lang="en">squid-urlregex-acl-bypass(15366)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-134.html" xml:lang="en">RHSA-2004:134</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-133.html" xml:lang="en">RHSA-2004:133</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/5916" xml:lang="en">5916</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:025" xml:lang="en">MDKSA-2004:025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2004/dsa-474" xml:lang="en">DSA-474</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200403-11.xml" xml:lang="en">GLSA-200403-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108084935904110&amp;w=2" xml:lang="en">20040401 [OpenPKG-SA-2004.008] OpenPKG Security  Advisory (squid)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000838" xml:lang="en">CLA-2004:838</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc" xml:lang="en">20040404-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.16/SCOSA-2005.16.txt" xml:lang="en">SCOSA-2005.16</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11354" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11354" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:941" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:941" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:877" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:877" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") characterm, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0190">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:symantec:firewall_vpn_appliance_100"/>
        <cpe-lang:fact-ref name="cpe:/h:symantec:firewall_vpn_appliance_200"/>
        <cpe-lang:fact-ref name="cpe:/h:symantec:firewall_vpn_appliance_200r"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:symantec:firewall_vpn_appliance_200r</vuln:product>
      <vuln:product>cpe:/h:symantec:firewall_vpn_appliance_100</vuln:product>
      <vuln:product>cpe:/h:symantec:firewall_vpn_appliance_200</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0190</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:28.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9784" xml:lang="en">9784</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15212" xml:lang="en">symantec-firewallvpn-password-plaintext(15212)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107694794031839&amp;w=2" xml:lang="en">20040216 Symantec FireWall/VPN Appliance model 200 leak of security</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/4117" xml:lang="en">4117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017414.html" xml:lang="en">20040216 Symantec FireWall/VPN Appliance model 200 leak of security</vuln:reference>
    </vuln:references>
    <vuln:summary>Symantec FireWall/VPN Appliance model 200 records a cleartext password for the password administration page, which may be cached on the administrator's local system or in a proxy, which allows attackers to steal the password and gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0191">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.35"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.48"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.2:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.2:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.2:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.2.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.4:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.4.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.3.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.48</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.35</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.4.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.2:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.2.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.4:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0191</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:46.303-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:937" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:937" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:874" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:874" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15322" xml:lang="en">mozilla-event-handler-xss(15322)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9747" xml:lang="en">9747</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107774710729469&amp;w=2" xml:lang="en">20040225 Sandblad #13: Cross-domain exploit on zombie document with event handlers</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.mozilla.org/show_bug.cgi?id=227417" xml:lang="en">http://bugzilla.mozilla.org/show_bug.cgi?id=227417</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-112.html" xml:lang="en">RHSA-2004:112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2004-110.html" xml:lang="en">RHSA-2004:110</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/4062" xml:lang="en">4062</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108448379429944&amp;w=2" xml:lang="en">SSRT4722</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:874" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:874" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:937" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:937" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10838" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10838" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0192">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:symantec:gateway_security_5400:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:symantec:gateway_security_5400:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0192</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:46.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9755" xml:lang="en">9755</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107790684732458&amp;w=2" xml:lang="en">20040227 Symantec Gateway Security Management Service Cross Site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15330" xml:lang="en">symantecgateway-error-xss(15330)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the resulting error page.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0193">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:iss:blackice_agent_server:3.6eca"/>
        <cpe-lang:fact-ref name="cpe:/a:iss:blackice_pc_protection:3.6cbd"/>
        <cpe-lang:fact-ref name="cpe:/a:iss:blackice_server_protection:3.6cbz"/>
        <cpe-lang:fact-ref name="cpe:/a:iss:realsecure_desktop:3.6eca"/>
        <cpe-lang:fact-ref name="cpe:/a:iss:realsecure_desktop:3.6ecf"/>
        <cpe-lang:fact-ref name="cpe:/a:iss:realsecure_desktop:7.0ebg"/>
        <cpe-lang:fact-ref name="cpe:/a:iss:realsecure_desktop:7.0epk"/>
        <cpe-lang:fact-ref name="cpe:/a:iss:realsecure_guard:3.6ecb"/>
        <cpe-lang:fact-ref name="cpe:/a:iss:realsecure_network:7.0:xpu_20.15"/>
        <cpe-lang:fact-ref name="cpe:/a:iss:realsecure_sentry:3.6ecf"/>
        <cpe-lang:fact-ref name="cpe:/a:iss:realsecure_server_sensor:7.0:xpu20.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:iss:proventia_a_series_xpu:20.15"/>
        <cpe-lang:fact-ref name="cpe:/h:iss:proventia_g_series_xpu:22.3"/>
        <cpe-lang:fact-ref name="cpe:/h:iss:proventia_m_series_xpu:1.30"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:iss:proventia_g_series_xpu:22.3</vuln:product>
      <vuln:product>cpe:/h:iss:proventia_m_series_xpu:1.30</vuln:product>
      <vuln:product>cpe:/a:iss:realsecure_network:7.0:xpu_20.15</vuln:product>
      <vuln:product>cpe:/a:iss:realsecure_desktop:3.6eca</vuln:product>
      <vuln:product>cpe:/a:iss:realsecure_desktop:3.6ecf</vuln:product>
      <vuln:product>cpe:/a:iss:blackice_pc_protection:3.6cbd</vuln:product>
      <vuln:product>cpe:/a:iss:realsecure_desktop:7.0ebg</vuln:product>
      <vuln:product>cpe:/h:iss:proventia_a_series_xpu:20.15</vuln:product>
      <vuln:product>cpe:/a:iss:blackice_server_protection:3.6cbz</vuln:product>
      <vuln:product>cpe:/a:iss:realsecure_guard:3.6ecb</vuln:product>
      <vuln:product>cpe:/a:iss:realsecure_sentry:3.6ecf</vuln:product>
      <vuln:product>cpe:/a:iss:realsecure_desktop:7.0epk</vuln:product>
      <vuln:product>cpe:/a:iss:realsecure_server_sensor:7.0:xpu20.16</vuln:product>
      <vuln:product>cpe:/a:iss:blackice_agent_server:3.6eca</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0193</vuln:cve-id>
    <vuln:published-datetime>2004-03-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:46.677-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/150326" xml:lang="en">VU#150326</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/alerts/id/165" xml:lang="en">20040226 Vulnerability in SMB Parsing in ISS Products</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.eeye.com/html/Research/Upcoming/20040213.html" xml:lang="en">http://www.eeye.com/html/Research/Upcoming/20040213.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15207" xml:lang="en">pam-smb-protocol-bo(15207)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9752" xml:lang="en">9752</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/4072" xml:lang="en">4072</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EEYE</vuln:source>
      <vuln:reference href="http://www.eeye.com/html/Research/Advisories/AD20040226.html" xml:lang="en">AD20040226</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/10988" xml:lang="en">10988</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107789851117176&amp;w=2" xml:lang="en">20040227 EEYE: RealSecure/BlackICE Server Message Block (SMB) Processing Overflow</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Proventia A, G, and M Series, RealSecure Desktop 7.0 and 3.6, RealSecure Guard 3.6, RealSecure Sentry 3.6, BlackICE PC Protection 3.6, and BlackICE Server Protection 3.6, allows remote attackers to execute arbitrary code via an SMB packet containing an authentication request with a long username.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0194">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat_reader:5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0194</vuln:cve-id>
    <vuln:published-datetime>2004-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:46.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9802" xml:lang="en">9802</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nextgenss.com/advisories/adobexfdf.txt" xml:lang="en">http://www.nextgenss.com/advisories/adobexfdf.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15384" xml:lang="en">acrobatreader-xfdf-bo(15384)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/4135" xml:lang="en">4135</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107842545022724&amp;w=2" xml:lang="en">20040303 Abobe Reader 5.1 XFDF Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018227.html" xml:lang="en">20040303 Adobe Acrobat Reader XML Forms Data Format Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the OutputDebugString function for Adobe Acrobat Reader 5.1 allows remote attackers to execute arbitrary code via a PDF document with XML Forms Data Format (XFDF) data.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0197">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:jet:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:jet:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0197</vuln:cve-id>
    <vuln:published-datetime>2004-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:28.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:968" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:968" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/740716" xml:lang="en">VU#740716</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" xml:lang="en">TA04-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/15703" xml:lang="en">msjet-query-execute-code(15703)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10112" xml:lang="en">10112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms04-014.asp" xml:lang="en">MS04-014</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:968" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:968" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in Microsoft Jet Database Engine 4.0 allows remote attackers to execute arbitrary code via a specially-crafted database query.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0199">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0199</vuln:cve-id>
    <vuln:published-datetime>2004-06-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:29.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1032" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1032" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1008" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1008" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/484814" xml:lang="en">VU#484814</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/16095" xml:lang="en">win-hcp-code-execution(16095)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10321" xml:lang="en">10321</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/MS04-015.mspx" xml:lang="en">MS04-015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108437759930820&amp;w=2" xml:lang="en">20040512 MS04-015 - Windows Help Center - Dvdupgrade</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.exploitlabs.com/files/advisories/EXPL-A-2004-001-helpctr.txt" xml:lang="en">http://www.exploitlabs.com/files/advisories/EXPL-A-2004-001-helpctr.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108430407801825&amp;w=2" xml:lang="en">20040512 MS04-015 - Windows Help Center - Dvdupgrade</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1008" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1008" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1032" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1032" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).</vuln:summary>
  </entry>
  <entry id="CVE-2004-0200">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.0:sp2:sdk"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:digital_image_pro:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:digital_image_pro:9"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:digital_image_suite:9"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:frontpage:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:frontpage:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:greetings:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:infopath:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003::student_teacher"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:onenote:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:picture_it:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:picture_it:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:picture_it:9"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:producer::gold:office_powerpoints"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:project:2002:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:project:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2002:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_basic:2002::.net_standard"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_basic:2003::.net_standard"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_c%23:2002::.net_standard"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_c%23:2003::.net_standard"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_c%2B%2B:2002::.net_standard"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_c%2B%2B:2003::.net_standard"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_j%23_.net:2003::.net_standard"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_studio_.net:2002:gold"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_studio_.net:2003:gold"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.0:sp2:sdk</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:frontpage:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:digital_image_pro:9</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_studio_.net:2003:gold</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003::student_teacher</vuln:product>
      <vuln:product>cpe:/a:microsoft:publisher:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:greetings:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:digital_image_suite:9</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_c%23:2002::.net_standard</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:tablet_pc</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_j%23_.net:2003::.net_standard</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:digital_image_pro:7.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_basic:2003::.net_standard</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2002</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_c%2B%2B:2002::.net_standard</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:picture_it:9</vuln:product>
      <vuln:product>cpe:/a:microsoft:producer::gold:office_powerpoints</vuln:product>
      <vuln:product>cpe:/a:microsoft:project:2002:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:visio:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:frontpage:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:onenote:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_c%2B%2B:2003::.net_standard</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_c%23:2003::.net_standard</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2003</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2002</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_basic:2002::.net_standard</vuln:product>
      <vuln:product>cpe:/a:microsoft:visio:2002:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:infopath:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:project:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:publisher:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:picture_it:7.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:picture_it:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_studio_.net:2002:gold</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0200</vuln:cve-id>
    <vuln:published-datetime>2004-09-28T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:29.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4307" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4307" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4216" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4216" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4003" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4003" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3881" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3881" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3810" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3810" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3320" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3320" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3082" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3082" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3038" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3038" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2706" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2706" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1721" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1721" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1105" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1105" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-260A.html" xml:lang="en">TA04-260A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/297462" xml:lang="en">VU#297462</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/16304" xml:lang="en">win-jpeg-bo(16304)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms04-028.asp" xml:lang="en">MS04-028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109524346729948&amp;w=2" xml:lang="en">20040914 Microsoft GDIPlus.DLL JPEG Parsing Engine Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2706" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2706" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3881" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3881" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1105" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1105" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4003" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4003" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4216" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4216" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1721" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1721" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3320" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3320" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4307" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4307" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3038" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3038" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3810" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3810" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3082" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3082" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0201">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:avaya:ip600_media_servers"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:definity_one_media_server"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:s8100"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:avaya:modular_messaging_message_storage_server:s3400"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/h:avaya:definity_one_media_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:datacenter_server</vuln:product>
      <vuln:product>cpe:/a:avaya:ip600_media_servers</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/h:avaya:s8100</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:avaya:modular_messaging_message_storage_server:s3400</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:advanced_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0201</vuln:cve-id>
    <vuln:published-datetime>2004-08-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:29.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3179" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3179" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2155" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2155" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1530" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1530" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1503" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1503" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-196A.html" xml:lang="en">TA04-196A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/920060" xml:lang="en">VU#920060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/MS04-023.mspx" xml:lang="en">MS04-023</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/16586" xml:lang="en">win-htmlhelp-execute-code(16586)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023919.html" xml:lang="en">20040714 HtmlHelp - .CHM File Heap Overflow</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3179" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3179" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1503" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1503" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1530" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1530" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2155" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2155" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0202">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:7.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:8.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:8.1a"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:8.1b"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:9.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:9.0b"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:directx:7.0a</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:9.0b</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:8.0a</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:8.2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:7.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:8.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:9.0a</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:8.1b</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:8.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:8.1a</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:7.1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:professional</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0202</vuln:cve-id>
    <vuln:published-datetime>2004-08-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:29.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2705" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2705" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2516" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2516" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2413" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2413" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2190" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2190" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1027" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1027" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10487" xml:lang="en">10487</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms04-016.asp" xml:lang="en">MS04-016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/16306" xml:lang="en">ms-directx-directplay-dos(16306)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6742" xml:lang="en">6742</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11802" xml:lang="en">11802</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1027" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1027" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2705" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2705" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2413" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2413" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2516" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2516" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2190" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2190" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0203">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5:sp4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5:sp4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0203</vuln:cve-id>
    <vuln:published-datetime>2004-11-23T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:29.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity approximated="true">MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2016" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2016" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/948750" xml:lang="en">VU#948750</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms04-026.mspx" xml:lang="en">MS04-026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/16583" xml:lang="en">exchange-owa-execute-code(16583)</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2016" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2016" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to insert arbitrary script and spoof content in HTML email or web caches via an HTML redirect query.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0204">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1::express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1::win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp1:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp2:win32"/>
        <cpe-lang:fact-ref name="cpe:/a:borland_software:j_builder"/>
        <cpe-lang:fact-ref name="cpe:/a:businessobjects:crystal_enterprise:10"/>
        <cpe-lang:fact-ref name="cpe:/a:businessobjects:crystal_enterprise:9"/>
        <cpe-lang:fact-ref name="cpe:/a:businessobjects:crystal_enterprise_java_sdk:8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:businessobjects:crystal_enterprise_ras:8.5::unix"/>
        <cpe-lang:fact-ref name="cpe:/a:businessobjects:crystal_reports:10"/>
        <cpe-lang:fact-ref name="cpe:/a:businessobjects:crystal_reports:9"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:business_solutions_crm:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2003::business_contact_manager"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_studio_.net:2003:gold"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:businessobjects:crystal_enterprise_ras:8.5::unix</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp1:express</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_studio_.net:2003:gold</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp2:express</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2003::business_contact_manager</vuln:product>
      <vuln:product>cpe:/a:businessobjects:crystal_enterprise:10</vuln:product>
      <vuln:product>cpe:/a:businessobjects:crystal_reports:9</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1::win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp1:win32</vuln:product>
      <vuln:product>cpe:/a:businessobjects:crystal_reports:10</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1::express</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp2:win32</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:business_solutions_crm:1.2</vuln:product>
      <vuln:product>cpe:/a:businessobjects:crystal_enterprise_java_sdk:8.5</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp2</vuln:product>
      <vuln:product>cpe:/a:businessobjects:crystal_enterprise:9</vuln:product>
      <vuln:product>cpe:/a:borland_software:j_builder</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0204</vuln:cve-id>
    <vuln:published-datetime>2004-08-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:30.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1157" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1157" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10260" xml:lang="en">10260</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/16044" xml:lang="en">crystalreports-file-deletion(16044)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms04-017.asp" xml:lang="en">MS04-017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.businessobjects.com/fix/hot/critical/bulletins/security_bulletin_june04.asp" xml:lang="en">http://support.businessobjects.com/fix/hot/critical/bulletins/security_bulletin_june04.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6748" xml:lang="en">6748</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/11800" xml:lang="en">11800</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108671836127360&amp;w=2" xml:lang="en">20040608 Vulnerability: Arbitrary File Access &amp; DoS in Crystal Reports</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360413811017&amp;w=2" xml:lang="en">20040502 Crystal Reports Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1157" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1157" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0205">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:avaya:ip600_media_servers"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:4.0"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:definity_one_media_server"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:s8100"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:avaya:modular_messaging_message_storage_server:s3400"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:avaya:ip600_media_servers</vuln:product>
      <vuln:product>cpe:/h:avaya:s8100</vuln:product>
      <vuln:product>cpe:/o:avaya:modular_messaging_message_storage_server:s3400</vuln:product>
      <vuln:product>cpe:/h:avaya:definity_one_media_server</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0205</vuln:cve-id>
    <vuln:published-datetime>2004-08-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:30.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2204" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2204" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA04-196A.html" xml:lang="en">TA04-196A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/717748" xml:lang="en">VU#717748</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/16578" xml:lang="en">iis-redirect-bo(16578)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms04-021.asp" xml:lang="en">MS04-021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/o-179.shtml" xml:lang="en">O-179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/10706" xml:lang="en">10706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/7799" xml:lang="en">7799</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/12061" xml:lang="en">12061</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2204" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2204" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arbitrary code via the redirect function.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0206">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0206</vuln:cve-id>
    <vuln:published-datetime>2004-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:30.397-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6788" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6788" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5074" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5074" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4592" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4592" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3242" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3242" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3120" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3120" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2394" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2394" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1852" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1852" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/640488" xml:lang="en">VU#640488</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/17657" xml:lang="en">win-ms04031-patch(17657)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/16556" xml:lang="en">win-netdde-bo(16556)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms04-031.asp" xml:lang="en">MS04-031</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/12803/" xml:lang="en">12803</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11372" xml:lang="en">11372</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109786703930674&amp;w=2" xml:lang="en">20041013 Microsoft Windows NetDDE Service Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3120" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3120" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1852" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1852" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6788" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6788" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2394" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2394" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5074" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5074" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3242" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3242" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4592" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4592" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0207">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0207</vuln:cve-id>
    <vuln:published-datetime>2004-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:37:48.817-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/218526" xml:lang="en">VU#218526</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/17658" xml:lang="en">win-ms04032-patch(17658)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/16579" xml:lang="en">win-mngmt-api-gain-privileges(16579)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms04-032.asp" xml:lang="en">MS04-032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109777417922695&amp;w=2" xml:lang="en">20041013 SetWindowLong Shatter Attacks</vuln:reference>
    </vuln:references>
    <vuln:summary>"Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the SetWindowLong and SetWIndowLongPtr API functions.</vuln:summary>
  </entry>
  <entry id="CVE-2004-0208">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2004-0208</vuln:cve-id>
    <vuln:published-datetime>2004-11-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:25:31.023-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4762" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4762" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4316" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4316" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3953" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3953" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3161" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3161" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1751" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1751" system="http://oval.mitre.org/XMLSchem