<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" nvd_xml_version="2.0" pub_date="2009-11-07T03:40:00" xsi:schemaLocation="http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
    <entry id="CVE-2005-1247">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:novell:nsure_audit:1.0.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:novell:nsure_audit:1.0.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-1247</vuln:cve-id>
        <vuln:published-datetime>2004-01-15T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:48:38.453-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-10T16:39:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2004-01/0126.html">20040115 OpenSSL ASN.1 parsing bugs PoC / brute forcer</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cirt.dk/advisories/cirt-31-advisory.pdf">http://www.cirt.dk/advisories/cirt-31-advisory.pdf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097379.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097379.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0021.html">20050424 [CIRT.DK - Advisory] Novell Nsure Audit 1.0.1 Denial of Service</vuln:reference>
        </vuln:references>
        <vuln:summary>webadmin.exe in Novell Nsure Audit 1.0.1 allows remote attackers to cause a denial of service via malformed ASN.1 packets in corrupt client certificates to an SSL server, as demonstrated using an exploit for the OpenSSL ASN.1 parsing vulnerability.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0190">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0:::english" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0:::japanese" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0::german" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0_6.0.12.690" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0_beta" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5_6.0.12.1016_beta" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5_6.0.12.1040" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.0_beta</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.5_6.0.12.1040</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.0_6.0.12.690</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.0:::english</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realone_player:2.0</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.5_6.0.12.1016_beta</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.0:::japanese</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realone_player:1.0</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.0::german</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0190</vuln:cve-id>
        <vuln:published-datetime>2004-09-29T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:33.260-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.6</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T15:35:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/17551">realplayer-media-file-deletion(17551)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/11308">11308</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ngssoftware.com/advisories/real-02full.txt">http://www.ngssoftware.com/advisories/real-02full.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://service.real.com/help/faq/security/040928_player/EN/">http://service.real.com/help/faq/security/040928_player/EN/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/12672/">12672</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616160228843&amp;w=2">20050119 RealPlayer Arbitrary File Deletion Vulnerability (#NISR19012005f)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616160228843&amp;w=2">20050119 RealPlayer Arbitrary File Deletion Vulnerability (#NISR19012005f)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to delete arbitrary files via a Real Metadata Packages (RMP) file with a FILENAME tag containing .. (dot dot) sequences in a filename that ends with a ? (question mark) and an allowed file extension (e.g. .mp3), which bypasses the check for the file extension.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0188">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:athoc:athoc_toolbar" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:athoc:athoc_toolbar</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0188</vuln:cve-id>
        <vuln:published-datetime>2004-10-06T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:32.933-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T14:57:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/17628">athoc-toolbar-format-string(17628)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/11341">11341</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ngssoftware.com/advisories/athoc-01full.txt">http://www.ngssoftware.com/advisories/athoc-01full.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616363415176&amp;w=2">20050119 Multiple vulnerabilities in the AtHoc Toolbar (#NISR19012005c)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109710974324742&amp;w=2">20041006 Patch available for high risk flaws in the AtHoc Toolbar</vuln:reference>
        </vuln:references>
        <vuln:summary>Format string vulnerability in the SetBaseURL function in AtHoc toolbar allows remote attackers to execute arbitrary code via format string specifiers in an invalid URL that is recorded in the debug log.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0189">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0:::english" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0:::japanese" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0::german" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0_6.0.12.690" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0_beta" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5_6.0.12.1016_beta" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5_6.0.12.1040" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.0_beta</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.5_6.0.12.1040</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.0_6.0.12.690</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.0:::english</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realone_player:2.0</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.5_6.0.12.1016_beta</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.0:::japanese</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realone_player:1.0</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.0::german</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0189</vuln:cve-id>
        <vuln:published-datetime>2004-10-06T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:33.090-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T15:10:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/698390">VU#698390</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12311">12311</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://service.real.com/help/faq/security/040928_player/EN/">http://service.real.com/help/faq/security/040928_player/EN/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616636318261&amp;w=2">20050119 RealPlayer 'ShowPreferences' Buffer Overflow Vulnerability (#NISR19012005e)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>NTBUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/ntbugtraq/2005-q1/0046.html">20050119 RealPlayer 'ShowPreferences' Buffer Overflow Vulnerability (#NISR19012005e)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616636318261&amp;w=2">20050119 RealPlayer 'ShowPreferences' Buffer Overflow Vulnerability (#NISR19012005e)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</vuln:reference>
        </vuln:references>
        <vuln:summary>Stack-based buffer overflow in the HandleAction function in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to execute arbitrary code via a long ShowPreferences argument.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0192">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0:::english" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0:::japanese" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0::german" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0_6.0.12.690" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0_beta" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5_6.0.12.1016_beta" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5_6.0.12.1040" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.0_beta</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.5_6.0.12.1040</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.0_6.0.12.690</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.0:::english</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realone_player:2.0</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.5_6.0.12.1016_beta</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.0:::japanese</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realone_player:1.0</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.0::german</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0192</vuln:cve-id>
        <vuln:published-datetime>2004-10-06T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:33.637-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.6</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T15:48:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18984">realplayer-rjs-filenane-directory-traversal(18984)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ngssoftware.com/advisories/real-03full.txt">http://www.ngssoftware.com/advisories/real-03full.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://service.real.com/help/faq/security/040928_player/EN/">http://service.real.com/help/faq/security/040928_player/EN/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in the parsing of Skin file names in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an RJS filename.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0373">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:cyrus:sasl:1.5.24" />
                <cpe-lang:fact-ref name="cpe:/a:cyrus:sasl:1.5.27" />
                <cpe-lang:fact-ref name="cpe:/a:cyrus:sasl:1.5.28" />
                <cpe-lang:fact-ref name="cpe:/a:cyrus:sasl:2.1.10" />
                <cpe-lang:fact-ref name="cpe:/a:cyrus:sasl:2.1.11" />
                <cpe-lang:fact-ref name="cpe:/a:cyrus:sasl:2.1.12" />
                <cpe-lang:fact-ref name="cpe:/a:cyrus:sasl:2.1.13" />
                <cpe-lang:fact-ref name="cpe:/a:cyrus:sasl:2.1.14" />
                <cpe-lang:fact-ref name="cpe:/a:cyrus:sasl:2.1.15" />
                <cpe-lang:fact-ref name="cpe:/a:cyrus:sasl:2.1.16" />
                <cpe-lang:fact-ref name="cpe:/a:cyrus:sasl:2.1.17" />
                <cpe-lang:fact-ref name="cpe:/a:cyrus:sasl:2.1.18" />
                <cpe-lang:fact-ref name="cpe:/a:cyrus:sasl:2.1.18_r1" />
                <cpe-lang:fact-ref name="cpe:/a:cyrus:sasl:2.1.9" />
                <cpe-lang:fact-ref name="cpe:/a:openpkg:openpkg:2.1" />
                <cpe-lang:fact-ref name="cpe:/a:openpkg:openpkg:2.2" />
                <cpe-lang:fact-ref name="cpe:/a:suse:suse_cvsup:16.1h_36.i586" />
                <cpe-lang:fact-ref name="cpe:/o:conectiva:linux:10.0" />
                <cpe-lang:fact-ref name="cpe:/o:conectiva:linux:9.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.1" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.2" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.3" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.4" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.2" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.3" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.4" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.7" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.1" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.3" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.4" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.5" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.6" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.7" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.8" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.1" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.2" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.3" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.4" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.5" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.7" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.1" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.3" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.4" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.5" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.6" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.7" />
                <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.8" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:fedora_core:core_1.0" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:1.0::desktop" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.0" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.0::i386" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.1" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.2" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.0" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.0::enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.0::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.1" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.1::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.2" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.2::x86_64" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.7</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.5</vuln:product>
            <vuln:product>cpe:/o:suse:suse_linux:1.0::desktop</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.0.4</vuln:product>
            <vuln:product>cpe:/a:cyrus:sasl:1.5.27</vuln:product>
            <vuln:product>cpe:/a:cyrus:sasl:1.5.28</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.0.2</vuln:product>
            <vuln:product>cpe:/o:suse:suse_linux:9.2::x86_64</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.0.3</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.4</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.3</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.0.1</vuln:product>
            <vuln:product>cpe:/a:cyrus:sasl:1.5.24</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.2</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.1</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.0</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.1</vuln:product>
            <vuln:product>cpe:/a:suse:suse_cvsup:16.1h_36.i586</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
            <vuln:product>cpe:/o:suse:suse_linux:8.0::i386</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.3.1</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.3.3</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.3.4</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.3.5</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.3.6</vuln:product>
            <vuln:product>cpe:/a:cyrus:sasl:2.1.9</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.1.4</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.3.7</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.1.3</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.3.8</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.1.2</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.1.1</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.1</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.0</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.3</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
            <vuln:product>cpe:/o:suse:suse_linux:9.1::x86_64</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2.7</vuln:product>
            <vuln:product>cpe:/o:conectiva:linux:9.0</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
            <vuln:product>cpe:/o:suse:suse_linux:9.0</vuln:product>
            <vuln:product>cpe:/o:suse:suse_linux:9.1</vuln:product>
            <vuln:product>cpe:/o:suse:suse_linux:9.0::x86_64</vuln:product>
            <vuln:product>cpe:/o:suse:suse_linux:9.2</vuln:product>
            <vuln:product>cpe:/a:cyrus:sasl:2.1.14</vuln:product>
            <vuln:product>cpe:/a:cyrus:sasl:2.1.13</vuln:product>
            <vuln:product>cpe:/o:suse:suse_linux:8.2</vuln:product>
            <vuln:product>cpe:/a:cyrus:sasl:2.1.12</vuln:product>
            <vuln:product>cpe:/o:suse:suse_linux:8.1</vuln:product>
            <vuln:product>cpe:/a:cyrus:sasl:2.1.11</vuln:product>
            <vuln:product>cpe:/a:cyrus:sasl:2.1.10</vuln:product>
            <vuln:product>cpe:/a:openpkg:openpkg:2.2</vuln:product>
            <vuln:product>cpe:/a:cyrus:sasl:2.1.18</vuln:product>
            <vuln:product>cpe:/a:cyrus:sasl:2.1.17</vuln:product>
            <vuln:product>cpe:/a:cyrus:sasl:2.1.16</vuln:product>
            <vuln:product>cpe:/a:cyrus:sasl:2.1.15</vuln:product>
            <vuln:product>cpe:/a:openpkg:openpkg:2.1</vuln:product>
            <vuln:product>cpe:/o:suse:suse_linux:8.0</vuln:product>
            <vuln:product>cpe:/a:cyrus:sasl:2.1.18_r1</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.1</vuln:product>
            <vuln:product>cpe:/o:suse:suse_linux:9.0::enterprise_server</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.3</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.4</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.5</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.6</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.7</vuln:product>
            <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.8</vuln:product>
            <vuln:product>cpe:/o:redhat:fedora_core:core_1.0</vuln:product>
            <vuln:product>cpe:/o:conectiva:linux:10.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0373</vuln:cve-id>
        <vuln:published-datetime>2004-10-07T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:35:27.477-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T10:47:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/17642">cyrus-sasl-digestmda5-bo(17642)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/11347">11347</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.monkey.org/openbsd/archive/ports/0407/msg00265.html">[openbsd-ports] 20040717 UPDATE: cyrus-sasl-2.1.19</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.linuxcompatible.org/print42495.html">SUSE-SR:2005:006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200410-05.xml">GLSA-200410-05</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c?rev=1.171&amp;content-type=text/x-cvsweb-markup">https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c?rev=1.171&amp;content-type=text/x-cvsweb-markup</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c.diff?r1=1.170&amp;r2=1.171">https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c.diff?r1=1.170&amp;r2=1.171</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:054">MDKSA-2005:054</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0066">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:tcp:tcp" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:tcp:tcp</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0066</vuln:cve-id>
        <vuln:published-datetime>2004-12-22T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:13.120-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-02T14:35:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/13124">13124</vuln:reference>
        </vuln:references>
        <vuln:summary>The original design of TCP does not check that the TCP Acknowledgement number in an ICMP error message generated by an intermediate router is within the range of possible values for data that has already been acknowledged (aka "TCP acknowledgement number checking"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0067">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:tcp:tcp" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:tcp:tcp</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0067</vuln:cve-id>
        <vuln:published-datetime>2004-12-22T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:13.277-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-02T14:40:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/13124">13124</vuln:reference>
        </vuln:references>
        <vuln:summary>The original design of TCP does not require that port numbers be assigned randomly (aka "Port randomization"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0068">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:tcp:tcp" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:tcp:tcp</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0068</vuln:cve-id>
        <vuln:published-datetime>2004-12-22T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:13.417-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-02T14:44:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/13124">13124</vuln:reference>
        </vuln:references>
        <vuln:summary>The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0441">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:11.03.3::linux" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:11.5.1::digital_unix" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:11.5.1::hp" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:11.5.1::sun" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:11.5.1::win" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:11.5::digital_unix" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:11.5::hp" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:11.5::sun" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:11.5::win" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:11.9.2::digital_unix" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:11.9.2::hp" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:11.9.2::sun" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:11.9.2::win" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:12.0.1::digital_unix" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:12.0.1::hp" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:12.0.1::sun" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:12.0.1::win" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:12.0::digital_unix" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:12.0::hp" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:12.0::sun" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:12.0::win" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:12.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:12.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:12.5::digital_unix" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:12.5::hp" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:12.5::linux" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:12.5::sgi" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:12.5::sun" />
                <cpe-lang:fact-ref name="cpe:/a:sybase:adaptive_server_enterprise:12.5::win" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:11.5::sun</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:12.5.3</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:12.5::win</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:12.0::digital_unix</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:12.5.2</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:12.0.1::sun</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:11.9.2::win</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:11.5.1::win</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:12.5::linux</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:11.5.1::hp</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:12.0::hp</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:12.5::sun</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:12.0::sun</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:12.0.1::win</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:11.5.1::sun</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:12.5::sgi</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:11.03.3::linux</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:11.9.2::digital_unix</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:12.5::digital_unix</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:11.9.2::sun</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:11.5::win</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:11.5::hp</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:11.5::digital_unix</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:12.0.1::digital_unix</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:12.0.1::hp</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:11.5.1::digital_unix</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:11.9.2::hp</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:12.0::win</vuln:product>
            <vuln:product>cpe:/a:sybase:adaptive_server_enterprise:12.5::hp</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0441</vuln:cve-id>
        <vuln:published-datetime>2004-12-22T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:18.007-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T13:29:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19980">sybase-ase-install-java-bo(19980)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19979">sybase-ase-abstract-bo(19979)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19978">sybase-ase-declare-bo(19978)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19976">sybase-ase-convert-bo(19976)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19974">sybase-ase-attribvalid-bo(19974)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19354">sybase-adaptive-server(19354)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.sybase.com/detail?id=1034752">http://www.sybase.com/detail?id=1034752</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.sybase.com/detail?id=1034520">http://www.sybase.com/detail?id=1034520</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12080">12080</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/393851">20050321 Details of Sybase ASE bugs withheld</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13632">13632</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111272918117194&amp;w=2">20050405 Sybase ASE Multiple Security Issues (#NISR05042005)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/bugtraq/2004-12/0315.html">20041222 Sybase ASE 12.5.2 vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ngssoftware.com/advisories/sybase-ase.txt">http://www.ngssoftware.com/advisories/sybase-ase.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attrib_valid function, (2) covert function, (3) declare statement, or (4) a crafted query plan, or remote authenticated users with database owner or "sa" role privileges to execute arbitrary code via (5) a crafted install java statement.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0266">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sugarcrm:sugarcrm:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:sugarcrm:sugarcrm:1.0f" />
                <cpe-lang:fact-ref name="cpe:/a:sugarcrm:sugarcrm:1.0g" />
                <cpe-lang:fact-ref name="cpe:/a:sugarcrm:sugarcrm:1.1" />
                <cpe-lang:fact-ref name="cpe:/a:sugarcrm:sugarcrm:1.1a" />
                <cpe-lang:fact-ref name="cpe:/a:sugarcrm:sugarcrm:1.1b" />
                <cpe-lang:fact-ref name="cpe:/a:sugarcrm:sugarcrm:1.1c" />
                <cpe-lang:fact-ref name="cpe:/a:sugarcrm:sugarcrm:1.1d" />
                <cpe-lang:fact-ref name="cpe:/a:sugarcrm:sugarcrm:1.1e" />
                <cpe-lang:fact-ref name="cpe:/a:sugarcrm:sugarcrm:1.1f" />
                <cpe-lang:fact-ref name="cpe:/a:sugarcrm:sugarcrm:1.5d" />
                <cpe-lang:fact-ref name="cpe:/a:sugarcrm:sugarcrm:2.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:sugarcrm:sugarcrm:2.0.1a" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sugarcrm:sugarcrm:1.0f</vuln:product>
            <vuln:product>cpe:/a:sugarcrm:sugarcrm:1.0g</vuln:product>
            <vuln:product>cpe:/a:sugarcrm:sugarcrm:1.1f</vuln:product>
            <vuln:product>cpe:/a:sugarcrm:sugarcrm:1.1</vuln:product>
            <vuln:product>cpe:/a:sugarcrm:sugarcrm:1.0</vuln:product>
            <vuln:product>cpe:/a:sugarcrm:sugarcrm:1.5d</vuln:product>
            <vuln:product>cpe:/a:sugarcrm:sugarcrm:1.1b</vuln:product>
            <vuln:product>cpe:/a:sugarcrm:sugarcrm:1.1c</vuln:product>
            <vuln:product>cpe:/a:sugarcrm:sugarcrm:1.1d</vuln:product>
            <vuln:product>cpe:/a:sugarcrm:sugarcrm:2.0.1a</vuln:product>
            <vuln:product>cpe:/a:sugarcrm:sugarcrm:1.1e</vuln:product>
            <vuln:product>cpe:/a:sugarcrm:sugarcrm:2.0.1</vuln:product>
            <vuln:product>cpe:/a:sugarcrm:sugarcrm:1.1a</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0266</vuln:cve-id>
        <vuln:published-datetime>2005-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:48.353-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T13:36:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110461706232174&amp;w=2">20050101 Cross Site Scripting Vulnerabilities and Possible Code Execution</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18719">sugar-sales-index-xss(18719)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12113">12113</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in SugarCRM 1.X allows remote attackers to inject arbitrary web script or HTML via the (1) return_module, (2) return_action, (3) name, (4) module, or (5) record parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0268">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:flatnuke:flatnuke:2.5.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:flatnuke:flatnuke:2.5.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0268</vuln:cve-id>
        <vuln:published-datetime>2005-01-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:48.713-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T13:44:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18746">flatnuke-indexphp-xss(18746)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12150">12150</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110477752916772&amp;w=2">20050102 Multiple Vulnerabilities in FlatNuke</vuln:reference>
        </vuln:references>
        <vuln:summary>Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the url_avatar field.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0271">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:photopost:reviewpost_php_pro:1.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:photopost:reviewpost_php_pro:2.5" />
                <cpe-lang:fact-ref name="cpe:/a:photopost:reviewpost_php_pro:2.5.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:photopost:reviewpost_php_pro:2.5</vuln:product>
            <vuln:product>cpe:/a:photopost:reviewpost_php_pro:2.5.1</vuln:product>
            <vuln:product>cpe:/a:photopost:reviewpost_php_pro:1.0.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0271</vuln:cve-id>
        <vuln:published-datetime>2005-01-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:49.277-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T13:54:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18732">reviewpost-php-sql-injection(18732)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gulftech.org/?node=research&amp;article_id=00062-01022005">http://www.gulftech.org/?node=research&amp;article_id=00062-01022005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13697/">13697</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485682424110&amp;w=2">20050103 Serious Vulnerabilities In PhotoPost ReviewPost</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showcat.php or (2) product parameter to addfav.php.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0274">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:photopost:photopost_php_pro:4.85" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:photopost:photopost_php_pro:4.85</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0274</vuln:cve-id>
        <vuln:published-datetime>2005-01-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:49.760-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T14:08:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18744">photopost-php-showgallery-xss(18744)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12156">12156</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gulftech.org/?node=research&amp;article_id=00063-01032005">http://www.gulftech.org/?node=research&amp;article_id=00063-01032005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486165802196&amp;w=2">20050103 Multiple PhotoPost Pro Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13680/">13680</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) si, (3) page, or (4) ppuser parameters.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0280">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:jowood_productions:soldner_secret_wars:30830" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:jowood_productions:soldner_secret_wars:30830</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0280</vuln:cve-id>
        <vuln:published-datetime>2005-01-04T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:50.713-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T14:19:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18752">soldner-secret-wars-format-string(18752)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12162">12162</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13716">13716</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486654213504&amp;w=2">20050104 Socket termination, format string and XSS in Soldner Secret Wars</vuln:reference>
        </vuln:references>
        <vuln:summary>Format string vulnerability in Soldner Secret Wars 30830 and earlier allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in a message.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0283">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:david_barrett:qwikiwiki:1.4.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:david_barrett:qwikiwiki:1.4.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0283</vuln:cve-id>
        <vuln:published-datetime>2005-01-04T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:51.180-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T14:27:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18748">qwikiwiki-directory-traversal(18748)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12163">12163</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486832621053&amp;w=2">20050104 QWikiwiki directory traversal vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.qwikiwiki.com/index.php?page=QwikiVulnerability">http://www.qwikiwiki.com/index.php?page=QwikiVulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/12044">12044</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (dot dot) and a %00 at the end of the filename in the page parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0182">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mod_dosevasive:mod_dosevasive:1.8" />
                <cpe-lang:fact-ref name="cpe:/a:mod_dosevasive:mod_dosevasive:1.9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mod_dosevasive:mod_dosevasive:1.8</vuln:product>
            <vuln:product>cpe:/a:mod_dosevasive:mod_dosevasive:1.9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0182</vuln:cve-id>
        <vuln:published-datetime>2005-01-06T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:31.963-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T14:32:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18765">moddosevasive-symlink(18765)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12181">12181</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-01-01">http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-01-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547469530582&amp;w=2">20050111 Mod_dosevasive symlink and race vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13725">13725</vuln:reference>
        </vuln:references>
        <vuln:summary>The mod_dosevasive module 1.9 and earlier for Apache creates temporary files with predictable filenames, which could allow remote attackers to overwrite arbitrary files via a symlink attack.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0284">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:woltlab:burning_book:1.0_gold" />
                <cpe-lang:fact-ref name="cpe:/a:woltlab:burning_book:1.1.1e" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:woltlab:burning_book:1.0_gold</vuln:product>
            <vuln:product>cpe:/a:woltlab:burning_book:1.1.1e</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0284</vuln:cve-id>
        <vuln:published-datetime>2005-01-10T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:51.337-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T14:39:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18859">woltlab-book-addentry-sql-injection(18859)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548032401506&amp;w=2">20050110 Woltlab Burning Book addentry.php SQL Injection</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in addentry.php in Woltlab Burning Book 1.0 Gold, 1.1.1e, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the user-agent parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0287">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:bottomline:webseries_payment_application:4.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:bottomline:webseries_payment_application:4.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0287</vuln:cve-id>
        <vuln:published-datetime>2005-01-10T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:51.823-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T14:49:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18862">webseries-report-execution(18862)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548383812462&amp;w=2">20050110 Portcullis Security Advisory 05-009</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012854">1012854</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13821">13821</vuln:reference>
        </vuln:references>
        <vuln:summary>Bottomline Webseries Payment Application allows remote attackers to read arbitrary files on the network via a report template with modified ReportPath or ReportName values.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0097">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.0_patch2" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1_patch2" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_.stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_.stable5" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_stable5" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable2" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable7" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_stable7" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable1" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable2" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable3" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable5" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable7" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable1" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable3" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable5" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable3" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable9" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.6.stable1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:squid:squid:2.1_patch2</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_stable9</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable3</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable2</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.4_.stable6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable5</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.4_.stable7</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable1</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.4_.stable2</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable5</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.3_stable5</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable3</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable1</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_stable3</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.4_stable7</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.3_.stable5</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.3_.stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.6.stable1</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable7</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.0_patch2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0097</vuln:cve-id>
        <vuln:published-datetime>2005-01-11T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:18.607-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T01:17:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2005/0003/">2005-0003</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200501-25.xml">GLSA-200501-25</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13789">13789</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12220">12220</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012818">1012818</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</vuln:reference>
        </vuln:references>
        <vuln:summary>The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0108">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:mod_auth_radius:1.5.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:mod_auth_radius:1.5.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0108</vuln:cve-id>
        <vuln:published-datetime>2005-01-11T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:20.480-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T03:41:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18841">modauthradius-dos(18841)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-659">DSA-659</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-02">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-02</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548193312050&amp;w=2">20050111 Apache mod_auth_radius remote integer overflow</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12217">12217</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012829">1012829</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14046">14046</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13773">13773</vuln:reference>
        </vuln:references>
        <vuln:summary>Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0117">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:xshisen:xshisen:1.36" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:xshisen:xshisen:1.36</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0117</vuln:cve-id>
        <vuln:published-datetime>2005-01-11T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:22.213-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T05:56:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vuxml.org/freebsd/56971fa6-641c-11d9-a097-000854d03344.html">http://www.vuxml.org/freebsd/56971fa6-641c-11d9-a097-000854d03344.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=289784">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=289784</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in XShisen before 1.36 allows local users to execute arbitrary code via a long GECOS field.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0288">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:bottomline:webseries_payment_application:4.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:bottomline:webseries_payment_application:4.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0288</vuln:cve-id>
        <vuln:published-datetime>2005-01-11T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:51.977-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>3.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T15:09:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18860">webseries-pa-password-gain-access(18860)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12231">12231</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549684319400&amp;w=2">20050110 Portcullis Security Advisory 05-008</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012854">1012854</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13821">13821</vuln:reference>
        </vuln:references>
        <vuln:summary>The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authenticated users to change other users' passwords.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0376">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sergey_kiselev:sgallery:1.01" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sergey_kiselev:sgallery:1.01</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0376</vuln:cve-id>
        <vuln:published-datetime>2005-01-12T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:07.167-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T11:01:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18878">sgallery-file-include(18878)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.waraxe.us/advisory-39.html">http://www.waraxe.us/advisory-39.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012868">1012868</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13824">13824</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110557050700947&amp;w=2">20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030844.html">20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file inclusion vulnerability in SGallery 1.01 allows local and possibly remote attackers to execute arbitrary PHP code by modifying the DOCUMENT_ROOT parameter to reference a URL on a remote web server that contains (1) config.php or (2) sql_layer.php.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0456">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:5.0.2::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:5.0::linux" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:5.0::mac" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:5.1.0::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:5.1.1::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:5.12" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:5.12::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.1::linux" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.1::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.2::linux" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.2::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.3::linux" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.3::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.4::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.5::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0.6::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.0::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:6.10::linux" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0.1::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0.2::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0.3::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0_beta1::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.0_beta2::win32" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.10" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.11" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.11b" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.11j" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.20" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.20_beta1_build2981" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.21" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.22" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.23" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.50" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.51" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.52" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.53" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.54" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:9.10" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.1::linux</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:5.0.2::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:9.10</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.6</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.1</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0.2::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:5.0::mac</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:5.12</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:5.0::linux</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.6::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.11b</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.5::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:5.1.1::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.23</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.22</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.21</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.20</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0.3::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.3::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.4::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.11j</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0_beta2::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.2::linux</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.54</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.20_beta1_build2981</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0.1::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.50</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:5.12::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.51</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.52</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.53</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.11</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.10</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.0_beta1::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.1::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.3::linux</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:5.1.0::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:6.0.2::win32</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:6.10::linux</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0456</vuln:cve-id>
        <vuln:published-datetime>2005-01-12T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:20.773-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T14:44:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/882926">VU#882926</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.opera.com/linux/changelogs/754u2/">http://www.opera.com/linux/changelogs/754u2/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml">GLSA-200502-17</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13818/">13818</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18867">opera-data-dialog-spoofing(18867)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_31_opera.html">SUSE-SA:2005:031</vuln:reference>
        </vuln:references>
        <vuln:summary>Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow remote attackers to trick users into executing arbitrary code.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0069">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:vim_development_group:vim:6.3.011" />
                <cpe-lang:fact-ref name="cpe:/a:vim_development_group:vim:6.3.025" />
                <cpe-lang:fact-ref name="cpe:/a:vim_development_group:vim:6.3.030" />
                <cpe-lang:fact-ref name="cpe:/a:vim_development_group:vim:6.3.044" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:vim_development_group:vim:6.3.011</vuln:product>
            <vuln:product>cpe:/a:vim_development_group:vim:6.3.044</vuln:product>
            <vuln:product>cpe:/a:vim_development_group:vim:6.3.030</vuln:product>
            <vuln:product>cpe:/a:vim_development_group:vim:6.3.025</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0069</vuln:cve-id>
        <vuln:published-datetime>2005-01-13T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:13.573-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-02T15:01:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18870">vim-symlink(18870)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-122.html">RHSA-2005:122</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-036.html">RHSA-2005:036</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13841/">13841</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608387001863&amp;w=2">20050118 [USN-61-1] vim vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.fedora.us/show_bug.cgi?id=2343">FLSA:2343</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012938">1012938</vuln:reference>
        </vuln:references>
        <vuln:summary>The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0111">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mysql:maxdb:7.5.00</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0111</vuln:cve-id>
        <vuln:published-datetime>2005-01-13T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:21.260-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T04:28:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>IDEFENSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/application/poi/display?id=181&amp;type=vulnerabilities">20050113 MySQL MaxDB WebAgent websql logon Buffer Overflow Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12265">12265</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>IDEFENSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/application/poi/display?id=181&amp;type=vulnerabilities">20050113 MySQL MaxDB WebAgent websql logon Buffer Overflow Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012893">1012893</vuln:reference>
        </vuln:references>
        <vuln:summary>Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0381">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:forumkit:forumkit:1.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:forumkit:forumkit:1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0381</vuln:cve-id>
        <vuln:published-datetime>2005-01-13T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:35:28.023-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T11:10:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18880">forumkit-members-xss(18880)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12256">12256</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012895">1012895</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110563769413994&amp;w=2">20050113 XSS Vulnerability in ForumKIT</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in f.aspx in forumKIT 1.0 allows remote attackers to inject arbitrary web script or HTML via the members parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0740">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.1" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.2" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.3" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.4" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.5" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.6" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.7" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.8" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.9" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.1" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.2" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.3" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.4" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.5" />
                <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:openbsd:openbsd:2.6</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:2.7</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:2.8</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:2.9</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:2.2</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:2.3</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:2.4</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:2.5</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:2.0</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:2.1</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:3.0</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:3.4</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:3.3</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:3.2</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:3.1</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:3.6</vuln:product>
            <vuln:product>cpe:/o:openbsd:openbsd:3.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0740</vuln:cve-id>
        <vuln:published-datetime>2005-01-13T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:47:10.350-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-10T10:37:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12250">12250</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENBSD</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openbsd.org/errata35.html">20050111 027: RELIABILITY FIX: January 11, 2005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012861">1012861</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13819">13819</vuln:reference>
        </vuln:references>
        <vuln:summary>The TCP stack (tcp_input.c) in OpenBSD 3.5 and 3.6 allows remote attackers to cause a denial of service (system panic) via crafted values in the TCP timestamp option, which causes invalid arguments to be used when calculating the retransmit timeout.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0110">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:ie:6.0:sp2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0110</vuln:cve-id>
        <vuln:published-datetime>2005-01-14T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:21.107-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.6</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T04:22:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110569119106172&amp;w=2">20050114 Internet Explorer (SP2) - Remote File Download</vuln:reference>
        </vuln:references>
        <vuln:summary>Internet Explorer 6 on Windows XP SP2 allows remote attackers to bypass the file download warning dialog and possibly trick an unknowledgeable user into executing arbitrary code via a web page with a body element containing an onclick tag, as demonstrated using the createElement function.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0113">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sgi:irix:6.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0113</vuln:cve-id>
        <vuln:published-datetime>2005-01-14T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:21.590-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T04:44:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18894">irix-inpview-gain-privileges(18894)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>IDEFENSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/application/poi/display?id=182&amp;type=vulnerabilities">20050113 SGI IRIX inpview Design Error Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13858">13858</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12259">12259</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/12915">12915</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012894">1012894</vuln:reference>
        </vuln:references>
        <vuln:summary>inpview in SGI IRIX allows local users to execute arbitrary commands via the SUN_TTSESSION_CMD environment variable, which is executed by inpview without dropping privileges.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0094">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.0_patch2" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1_patch2" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_.stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_.stable5" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_stable5" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable2" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable7" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_stable7" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable1" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable2" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable3" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable5" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable7" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable1" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable3" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable5" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable3" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable9" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.6.stable1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:squid:squid:2.1_patch2</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_stable9</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable3</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable2</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.4_.stable6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable5</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.4_.stable7</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable1</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.4_.stable2</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable5</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.3_stable5</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable3</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable1</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_stable3</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.4_stable7</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.3_.stable5</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.3_.stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.6.stable1</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable7</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.0_patch2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0094</vuln:cve-id>
        <vuln:published-datetime>2005-01-15T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:34:55.413-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T00:28:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-651">DSA-651</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200501-25.xml">GLSA-200501-25</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13825">13825</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2005/0003/">2005-0003</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-gopher_html_parsing.patch">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-gopher_html_parsing.patch</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.squid-cache.org/Advisories/SQUID-2005_1.txt">http://www.squid-cache.org/Advisories/SQUID-2005_1.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923">CLA-2005:923</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12276">12276</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:014">MDKSA-2005:014</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0095">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.0_patch2" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1_patch2" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_.stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_.stable5" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_stable5" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable2" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable7" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_stable7" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable1" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable2" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable3" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable5" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable7" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable1" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable3" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable5" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable3" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable9" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.6.stable1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:squid:squid:2.1_patch2</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_stable9</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable3</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable2</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.4_.stable6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable5</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.4_.stable7</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable1</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.4_.stable2</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable5</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.3_stable5</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable3</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable1</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_stable3</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.4_stable7</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.3_.stable5</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.3_.stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.6.stable1</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable7</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.0_patch2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0095</vuln:cve-id>
        <vuln:published-datetime>2005-01-15T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:34:55.493-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T00:42:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2005/0003/">2005-0003</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.squid-cache.org/Advisories/SQUID-2005_2.txt">http://www.squid-cache.org/Advisories/SQUID-2005_2.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-651">DSA-651</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200501-25.xml">GLSA-200501-25</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13825">13825</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923">CLA-2005:923</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_denial_of_service.patch">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_denial_of_service.patch</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12275">12275</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/12886">12886</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:014">MDKSA-2005:014</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012882">1012882</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</vuln:reference>
        </vuln:references>
        <vuln:summary>The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCCP messages with source addresses that are spoofed to reference Squid's home router and invalid WCCP_I_SEE_YOU cache numbers.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0294">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:minis:minis:0.2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:minis:minis:0.2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0294</vuln:cve-id>
        <vuln:published-datetime>2005-01-16T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:52.917-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T15:36:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18929">minis-month-dos(18929)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599953704025&amp;w=2">20050116 Minis directory traversal vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030966.html">20050116 Minis directory traversal vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012911">1012911</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13866">13866</vuln:reference>
        </vuln:references>
        <vuln:summary>minis.php in Minis 0.2.1 allows remote attackers to cause a denial of service (infinite loop) via an HTTP request for a file that the web server does not have permission to read, as demonstrated using the month parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0221">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:gallery_project:gallery:2.0_alpha" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:gallery_project:gallery:2.0_alpha</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0221</vuln:cve-id>
        <vuln:published-datetime>2005-01-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:40.010-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T10:26:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18938">gallery-multiple-xss(18938)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://theinsider.deep-ice.com/texts/advisory69.txt">http://theinsider.deep-ice.com/texts/advisory69.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608459222364&amp;w=2">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VULNWATCH</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0031.html">20050117 [VulnWatch] Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/43472">gallery-g2formsubject-xss(43472)</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in login.php in Gallery 2.0 Alpha allows remote attackers to inject arbitrary web script or HTML via the g2_form[subject] field.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0290">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:netgear:fvs318:2.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:netgear:fvs318:2.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0290</vuln:cve-id>
        <vuln:published-datetime>2005-01-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:52.290-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T15:20:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18920">netgear-fvs318-filter-bypass(18920)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12278">12278</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599727631560&amp;w=2">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030984.html">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012913">1012913</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13787">13787</vuln:reference>
        </vuln:references>
        <vuln:summary>NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to bypass the filters using hex encoded URLs, as demonstrated using a hex encoded file extension.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0291">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:netgear:fvs318:2.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:netgear:fvs318:2.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0291</vuln:cve-id>
        <vuln:published-datetime>2005-01-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:52.447-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T15:27:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18921">netgear-fvs318-log-xss(18921)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12278">12278</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599727631560&amp;w=2">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030984.html">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/13012">13012</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012913">1012913</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13787">13787</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in the log viewer in NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via a blocked URL phrase.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0292">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:php_gift_registry:phpgiftreg:1.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:php_gift_registry:phpgiftreg:1.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0292</vuln:cve-id>
        <vuln:published-datetime>2005-01-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:52.603-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T15:32:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12289">12289</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/392485">20050307 Re: phpGiftReq SQL Injection</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18925">phpgiftregistry-sql-injection(18925)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13873">13873</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599710017066&amp;w=2">20050116 phpGiftReq SQL Injection</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030965.html">20050116 phpGiftReq SQL Injection</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012910">1012910</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple SQL injection vulnerabilities in index.php in PHP Gift Registry (phpGiftReg) 1.4.0, and possibly other versions before 1.5.0b1, allow remote attackers to execute arbitrary SQL commands via the (1) messageid, (2) shopper, (3) shopfor, or (4) itemid parameters.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0295">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:inca:nprotect_gameguard" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:inca:nprotect_gameguard</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0295</vuln:cve-id>
        <vuln:published-datetime>2005-01-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:53.073-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T15:41:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18952">nprotect-npptnt2-gain-access(18952)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12280">12280</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608422029555&amp;w=2">20050116 Unrestricted I/O access vulnerability in INCA Gameguard</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13928">13928</vuln:reference>
        </vuln:references>
        <vuln:summary>npptnt2.sys in nProtect Gameguard provides unrestricted I/O to any process that calls it, which allows local users to gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0296">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:novell:groupwise:6.0" />
                <cpe-lang:fact-ref name="cpe:/a:novell:groupwise:6.0:sp1" />
                <cpe-lang:fact-ref name="cpe:/a:novell:groupwise:6.0:sp2" />
                <cpe-lang:fact-ref name="cpe:/a:novell:groupwise:6.0:sp3" />
                <cpe-lang:fact-ref name="cpe:/a:novell:groupwise:6.0:sp4" />
                <cpe-lang:fact-ref name="cpe:/a:novell:groupwise:6.5" />
                <cpe-lang:fact-ref name="cpe:/a:novell:groupwise:6.5:sp1" />
                <cpe-lang:fact-ref name="cpe:/a:novell:groupwise:6.5:sp2" />
                <cpe-lang:fact-ref name="cpe:/a:novell:groupwise_webaccess:6.0:sp4" />
                <cpe-lang:fact-ref name="cpe:/a:novell:groupwise_webaccess:6.5" />
                <cpe-lang:fact-ref name="cpe:/a:novell:groupwise_webaccess:6.5:sp1" />
                <cpe-lang:fact-ref name="cpe:/a:novell:groupwise_webaccess:6.5:sp2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:novell:groupwise_webaccess:6.5:sp2</vuln:product>
            <vuln:product>cpe:/a:novell:groupwise:6.0:sp4</vuln:product>
            <vuln:product>cpe:/a:novell:groupwise:6.5:sp1</vuln:product>
            <vuln:product>cpe:/a:novell:groupwise:6.5:sp2</vuln:product>
            <vuln:product>cpe:/a:novell:groupwise:6.0</vuln:product>
            <vuln:product>cpe:/a:novell:groupwise:6.5</vuln:product>
            <vuln:product>cpe:/a:novell:groupwise:6.0:sp2</vuln:product>
            <vuln:product>cpe:/a:novell:groupwise_webaccess:6.5</vuln:product>
            <vuln:product>cpe:/a:novell:groupwise:6.0:sp3</vuln:product>
            <vuln:product>cpe:/a:novell:groupwise_webaccess:6.0:sp4</vuln:product>
            <vuln:product>cpe:/a:novell:groupwise_webaccess:6.5:sp1</vuln:product>
            <vuln:product>cpe:/a:novell:groupwise:6.0:sp1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0296</vuln:cve-id>
        <vuln:published-datetime>2005-01-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:53.227-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T15:51:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18954">groupwise-error-auth-bypass(18954)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12285">12285</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2005-01/0341.html">20050127 NOVL-2005-10096251 GroupWise WebAccess error handling modules (report)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2005-01/0771.html">20050121 NOVL-2005-10096251 GroupWise WebAccess error handling modules (report)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.novell.com/servlet/tidfinder/10096251">http://support.novell.com/servlet/tidfinder/10096251</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608203729814&amp;w=2">20050117 Novell GroupWise WebAccess error modules loading</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/13135">13135</vuln:reference>
        </vuln:references>
        <vuln:summary>** DISPUTED **  NOTE: this issue has been disputed by the vendor.  The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as the version, via an incorrect login and a modified (1) error or (2) modify parameter that returns template files or the "about" information page.  NOTE: the vendor has disputed this issue.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0116">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:awstats:awstats:6.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:awstats:awstats:6.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0116</vuln:cve-id>
        <vuln:published-datetime>2005-01-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:22.057-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T05:41:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-20" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/272296">VU#272296</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>IDEFENSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/application/poi/display?id=185&amp;type=vulnerabilities&amp;flashstatus=false">20050117 AWStats Remote Command Execution Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13893/">13893</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://awstats.sourceforge.net/docs/awstats_changelog.txt">http://awstats.sourceforge.net/docs/awstats_changelog.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12298">12298</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/13002">13002</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://packetstormsecurity.org/0501-exploits/AWStatsVulnAnalysis.pdf">http://packetstormsecurity.org/0501-exploits/AWStatsVulnAnalysis.pdf</vuln:reference>
        </vuln:references>
        <vuln:summary>AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0297">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:oracle:database_server" />
                <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:10.2.1:r2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:oracle:database_server</vuln:product>
            <vuln:product>cpe:/a:oracle:database_server:10.2.1:r2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0297</vuln:cve-id>
        <vuln:published-datetime>2005-01-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:53.417-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T16:07:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110606477308492&amp;w=2">20050118 Multiple high risk vulnerabilities in Oracle RDBMS 10g/9i</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitrary SQL commands and gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0186">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1yd" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2t" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3" />
                <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3t" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:cisco:ios:12.3t</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.3</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.1yd</vuln:product>
            <vuln:product>cpe:/o:cisco:ios:12.2t</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0186</vuln:cve-id>
        <vuln:published-datetime>2005-01-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-03-04T00:29:26.593-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T14:42:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:4849" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4849" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18956">cisco-ios-sccp-dos(18956)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CISCO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cisco.com/warp/public/707/cisco-sa-20050119-itscme.shtml">20050119 Vulnerability in Cisco IOS Embedded Call Processing Solutions</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012945">1012945</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13913">13913</vuln:reference>
        </vuln:references>
        <vuln:summary>Cisco IOS 12.1YD, 12.2T, 12.3 and 12.3T, when configured for the IOS Telephony Service (ITS), CallManager Express (CME) or Survivable Remote Site Telephony (SRST), allows remote attackers to cause a denial of service (device reboot) via a malformed packet to the SCCP port.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0191">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0:::english" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0:::japanese" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0::german" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0_6.0.12.690" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0_beta" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5_6.0.12.1016_beta" />
                <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5_6.0.12.1040" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.0_beta</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.5_6.0.12.1040</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.0_6.0.12.690</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.0:::english</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realone_player:2.0</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.5_6.0.12.1016_beta</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.0:::japanese</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realone_player:1.0</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.0::german</vuln:product>
            <vuln:product>cpe:/a:realnetworks:realplayer:10.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0191</vuln:cve-id>
        <vuln:published-datetime>2005-01-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:33.447-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.1</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T15:46:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18982">realplayer-long-filename-offbyone-bo(18982)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ngssoftware.com/advisories/real-03full.txt">http://www.ngssoftware.com/advisories/real-03full.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://service.real.com/help/faq/security/040928_player/EN/">http://service.real.com/help/faq/security/040928_player/EN/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</vuln:reference>
        </vuln:references>
        <vuln:summary>Off-by-one buffer overflow in the processing of tags in Real Metadata Package (RMP) files in RealPlayer 10.5 (6.0.12.1040) and earlier could allow remote attackers to execute arbitrary code via a long tag.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0300">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:jsboard:jsboard:2.0.7" />
                <cpe-lang:fact-ref name="cpe:/a:jsboard:jsboard:2.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:jsboard:jsboard:2.0.9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:jsboard:jsboard:2.0.7</vuln:product>
            <vuln:product>cpe:/a:jsboard:jsboard:2.0.8</vuln:product>
            <vuln:product>cpe:/a:jsboard:jsboard:2.0.9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0300</vuln:cve-id>
        <vuln:published-datetime>2005-01-20T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:53.930-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T16:23:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18990">jsboard-session-file-include(18990)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12319">12319</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110627201120011&amp;w=2">20050120 STG Security Advisory: [SSA-20050120-22] JSBoard file disclosure</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012949">1012949</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13920">13920</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in session.php in JSBoard 2.0.9 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the table parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2005-1846">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:yamt:yamt:0.5.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:yamt:yamt:0.5.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-1846</vuln:cve-id>
        <vuln:published-datetime>2005-01-20T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:50:14.887-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T15:14:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vuxml.org/freebsd/99b5cfa5-d3d2-11d9-8ffb-00061bc2ad93.html">http://www.vuxml.org/freebsd/99b5cfa5-d3d2-11d9-8ffb-00061bc2ad93.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html">http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple directory traversal vulnerabilities in YaMT before 0.5_2 allow attackers to overwrite arbitrary files via the (1) rename or (2) sort options.</vuln:summary>
    </entry>
    <entry id="CVE-2005-1847">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:yamt:yamt:0.5.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:yamt:yamt:0.5.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-1847</vuln:cve-id>
        <vuln:published-datetime>2005-01-20T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:50:15.027-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T15:20:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vuxml.org/freebsd/99b5cfa5-d3d2-11d9-8ffb-00061bc2ad93.html">http://www.vuxml.org/freebsd/99b5cfa5-d3d2-11d9-8ffb-00061bc2ad93.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html">http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple buffer overflows in YaMT before 0.5_2 allow attackers to execute arbitrary code via the (1) rename or (2) sort options.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0193">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:isync:mrouter:1.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:isync:mrouter:1.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0193</vuln:cve-id>
        <vuln:published-datetime>2005-01-22T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:33.807-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T15:52:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19011">isync-mrouter-bo(19011)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110642400018425&amp;w=2">20050122 Mac OS X 10.3 iSync Privilege Escalation</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2005/Apr/msg00001.html">APPLE-SA-2005-04-19</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12334">12334</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012974">1012974</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13965">13965</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute arbitrary code.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0566">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:kmint21_software:golden_ftp_server:1.00b" />
                <cpe-lang:fact-ref name="cpe:/a:kmint21_software:golden_ftp_server:1.20b" />
                <cpe-lang:fact-ref name="cpe:/a:kmint21_software:golden_ftp_server:1.30b" />
                <cpe-lang:fact-ref name="cpe:/a:kmint21_software:golden_ftp_server:1.31b" />
                <cpe-lang:fact-ref name="cpe:/a:kmint21_software:golden_ftp_server:2.02b" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:kmint21_software:golden_ftp_server:1.31b</vuln:product>
            <vuln:product>cpe:/a:kmint21_software:golden_ftp_server:1.00b</vuln:product>
            <vuln:product>cpe:/a:kmint21_software:golden_ftp_server:1.30b</vuln:product>
            <vuln:product>cpe:/a:kmint21_software:golden_ftp_server:2.02b</vuln:product>
            <vuln:product>cpe:/a:kmint21_software:golden_ftp_server:1.20b</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0566</vuln:cve-id>
        <vuln:published-datetime>2005-01-22T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:39.570-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-08T11:21:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/620862">VU#620862</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19015">golden-ftp-rnto-bo(19015)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12333">12333</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.goldenftpserver.com">http://www.goldenftpserver.com</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13966/">13966</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012973">1012973</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031098.html">20050122 several BO's in goldenftpd</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in Golden FTP Server Pro (goldenftpd) 2.x allows remote attackers to execute arbitrary code via a long RNTO command.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0072">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ejoy_and_hu_yong:zhcon:0.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ejoy_and_hu_yong:zhcon:0.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0072</vuln:cve-id>
        <vuln:published-datetime>2005-01-24T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:34:51.897-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-02T15:22:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-655">DSA-655</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19045">zhcon-information-disclosure(19045)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12343">12343</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:012">MDKSA-2005:012</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012977">1012977</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13987">13987</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13982">13982</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13977">13977</vuln:reference>
        </vuln:references>
        <vuln:summary>zhcon before 0.2 does not drop privileges before reading a user configuration file, which allows local users to read arbitrary files.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0145">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9:rc" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.9:rc</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.10</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.9.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.9.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.9.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.10.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0145</vuln:cve-id>
        <vuln:published-datetime>2005-01-24T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:35:02.290-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.6</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T12:29:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:100051" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100051" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=265176">https://bugzilla.mozilla.org/show_bug.cgi?id=265176</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19170">mozilla-script-click-event-bypass(19170)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/mfsa2005-07.html">http://www.mozilla.org/security/announce/mfsa2005-07.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12407">12407</vuln:reference>
        </vuln:references>
        <vuln:summary>Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0115">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:datarescue:ida:4.7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:datarescue:ida:4.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0115</vuln:cve-id>
        <vuln:published-datetime>2005-01-24T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:21.903-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T05:24:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19042">database-ida-portable-executable-bo(19042)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.datarescue.com/ubb/ultimatebb.php?/topic/2/146.html">http://www.datarescue.com/ubb/ultimatebb.php?/topic/2/146.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>IDEFENSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/application/poi/display?id=189&amp;type=vulnerabilities">20050124 DataRescue Interactive Disassembler Pro Buffer Overflow Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12353">12353</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012975">1012975</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13980">13980</vuln:reference>
        </vuln:references>
        <vuln:summary>Stack-based buffer overflow in DataRescue Interactive Disassembler (IDA) Pro 4.7 allows attackers to execute arbitrary code via a PE file with an Import Address Table containing a long import library name.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0102">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.3.2_beta" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ximian:evolution:1.3.2_beta</vuln:product>
            <vuln:product>cpe:/a:ximian:evolution:1.2.4</vuln:product>
            <vuln:product>cpe:/a:ximian:evolution:1.2.3</vuln:product>
            <vuln:product>cpe:/a:ximian:evolution:1.2.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0102</vuln:cve-id>
        <vuln:published-datetime>2005-01-24T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:34:57.570-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T02:09:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19031">evolution-camellockhelper-bo(19031)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12354">12354</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-397.html">RHSA-2005:397</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-673">DSA-673</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200501-35.xml">GLSA-200501-35</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000925">CLA-2005:925</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-238.html">RHSA-2005:238</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntulinux.org/support/documentation/usn/usn-69-1">USN-69-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:024">MDKSA-2005:024</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012981">1012981</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13830">13830</vuln:reference>
        </vuln:references>
        <vuln:summary>Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0103">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.10" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.11" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.5" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.6" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.7" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.8" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.9" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.0" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.2" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3_rc1" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3a" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.0</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.0.5</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.0.4</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.1</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.2</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3_rc1</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.8</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.7</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.9</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.4</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.3</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.10</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.6</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3a</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.11</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.5</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.0</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.2</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0103</vuln:cve-id>
        <vuln:published-datetime>2005-01-24T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:19.607-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T02:31:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.squirrelmail.org/security/issue/2005-01-19?PHPSESSID=8af117822fb1ca3aa966a64248b5d223">http://www.squirrelmail.org/security/issue/2005-01-19?PHPSESSID=8af117822fb1ca3aa966a64248b5d223</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-135.html">RHSA-2005:135</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-099.html">RHSA-2005:099</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13962/">13962</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml">GLSA-200501-39</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2">20050129 SquirrelMail Security Advisory</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19037">squirrelmail-frame-file-include(19037)</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by modifying a URL parameter to reference a URL on a remote web server that contains the code.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0072">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ejoy_and_hu_yong:zhcon:0.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ejoy_and_hu_yong:zhcon:0.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0072</vuln:cve-id>
        <vuln:published-datetime>2005-01-24T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:34:51.897-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-02T15:22:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-655">DSA-655</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19045">zhcon-information-disclosure(19045)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12343">12343</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:012">MDKSA-2005:012</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012977">1012977</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13987">13987</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13982">13982</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13977">13977</vuln:reference>
        </vuln:references>
        <vuln:summary>zhcon before 0.2 does not drop privileges before reading a user configuration file, which allows local users to read arbitrary files.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0096">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.0_patch2" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1_patch2" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_.stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_.stable5" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_stable5" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable2" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable7" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_stable7" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable1" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable2" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable3" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable5" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable7" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable1" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable3" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable5" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable3" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable9" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.6.stable1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:squid:squid:2.1_patch2</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_stable9</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable3</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable2</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.4_.stable6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable5</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.4_.stable7</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable1</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.4_.stable2</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable5</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.3_stable5</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable3</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable1</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_stable3</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.4_stable7</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.3_.stable5</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.3_.stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.6.stable1</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable7</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.0_patch2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0096</vuln:cve-id>
        <vuln:published-datetime>2005-01-25T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:18.370-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T00:50:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200501-25.xml">GLSA-200501-25</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923">CLA-2005:923</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2005/0003/">2005-0003</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12324">12324</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1012818">1012818</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</vuln:reference>
        </vuln:references>
        <vuln:summary>Memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (memory consumption).</vuln:summary>
    </entry>
    <entry id="CVE-2005-0309">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:exponent:exponent:0.95" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:exponent:exponent:0.95</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0309</vuln:cve-id>
        <vuln:published-datetime>2005-01-25T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:55.370-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T17:03:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19061">exponent-module-xss(19061)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12358">12358</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110666998407073&amp;w=2">20050125 Vulnerabilities in eXponent 0.95</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/13190">13190</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/13188">13188</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitrary web script or HTML via the module parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0306">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mercuryboard:mercuryboard:1.1" />
                <cpe-lang:fact-ref name="cpe:/a:mercuryboard:mercuryboard:1.1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mercuryboard:mercuryboard:1.1</vuln:product>
            <vuln:product>cpe:/a:mercuryboard:mercuryboard:1.1.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0306</vuln:cve-id>
        <vuln:published-datetime>2005-01-25T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:54.883-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T16:28:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19048">mercuryboard-multiple-script-path-disclosure(19048)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12359">12359</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110661795632354&amp;w=2">20050124 Multiple vulnerabilities in MercuryBoard 1.1.1</vuln:reference>
        </vuln:references>
        <vuln:summary>MercuryBoard 1.1.1 allows remote attackers to gain sensitive information via an HTTP request with the n parameter set to 0, which causes a divide-by-zero error and reveals the path in the resulting error message.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0307">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mercuryboard:mercuryboard:1.1" />
                <cpe-lang:fact-ref name="cpe:/a:mercuryboard:mercuryboard:1.1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mercuryboard:mercuryboard:1.1</vuln:product>
            <vuln:product>cpe:/a:mercuryboard:mercuryboard:1.1.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0307</vuln:cve-id>
        <vuln:published-datetime>2005-01-25T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:55.057-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T16:43:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19050">mercuryboard-multiple-scripts-xss(19050)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12359">12359</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110661795632354&amp;w=2">20050124 Multiple vulnerabilities in MercuryBoard 1.1.1</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) s, (2) l, (3) a, (4) t, (5) to, or (6) re parameters.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0162">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:openswan:openswan:2.3.0" />
                <cpe-lang:fact-ref name="cpe:/a:openswan:openswan:1.0.9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:openswan:openswan:1.0.9</vuln:product>
            <vuln:product>cpe:/a:openswan:openswan:2.3.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0162</vuln:cve-id>
        <vuln:published-datetime>2005-01-26T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:29.260-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T13:21:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19078">openswan-xauth-pam-bo(19078)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openswan.org/support/vuln/IDEF0785/">http://www.openswan.org/support/vuln/IDEF0785/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>IDEFENSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/application/poi/display?id=190&amp;type=vulnerabilities">20050126 Openswan XAUTH/PAM Buffer Overflow Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12377">12377</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/archives/fedora-announce-list/2005-January/msg00103.html">FEDORA-2005-082</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/13195">13195</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1013014">1013014</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14062">14062</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14038">14038</vuln:reference>
        </vuln:references>
        <vuln:summary>Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH and PAM enabled, allows remote authenticated attackers to execute arbitrary code.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0312">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:war_ftp_daemon:war_ftp_daemon:1.8" />
                <cpe-lang:fact-ref name="cpe:/a:war_ftp_daemon:war_ftp_daemon:1.82_rc9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:war_ftp_daemon:war_ftp_daemon:1.8</vuln:product>
            <vuln:product>cpe:/a:war_ftp_daemon:war_ftp_daemon:1.82_rc9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0312</vuln:cve-id>
        <vuln:published-datetime>2005-01-27T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:55.853-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T17:09:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12384">12384</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110687202332039&amp;w=2">20050127 WarFTPD 1.82 RC9 DoS</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19129">warftpd-cwd-dos(19129)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.jgaa.com/index.php?cmd=ShowReport&amp;ID=02643">http://support.jgaa.com/index.php?cmd=ShowReport&amp;ID=02643</vuln:reference>
        </vuln:references>
        <vuln:summary>WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of "%s" sequences, possibly indicating a format string vulnerability.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0313">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:amax_information_technologies:magic_winmail_server:4.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:amax_information_technologies:magic_winmail_server:4.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0313</vuln:cve-id>
        <vuln:published-datetime>2005-01-27T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:56.010-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T17:16:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19114">magic-winmail-command-directory-traversal(19114)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19108">magicwinmail-uploadphp-file-upload(19108)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12388">12388</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1013017">1013017</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14053">14053</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110685011825461&amp;w=2">20050127 [SIG^2 G-TEC] Magic Winmail Server v4.0 Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote authenticated users to read, create, or delete arbitrary directories and files via the IMAP commands (3) CREATE, (4) EXAMINE, (5) SELECT, or (6) DELETE.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0314">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:amax_information_technologies:magic_winmail_server:4.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:cve-id>CVE-2005-0314</vuln:cve-id>
        <vuln:published-datetime>2005-01-27T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:56.167-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T17:17:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19113">magic-winmail-userphp-xss(19113)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12388">12388</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110685011825461&amp;w=2">20050127 [SIG^2 G-TEC] Magic Winmail Server v4.0 Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1013017">1013017</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14053">14053</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in user.php in Magic Winmail Server 4.0 Build 1112 allows remote attackers to inject arbitrary web script or HTML via the personal information fields.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0315">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:amax_information_technologies:magic_winmail_server:4.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:amax_information_technologies:magic_winmail_server:4.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0315</vuln:cve-id>
        <vuln:published-datetime>2005-01-27T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:56.323-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T17:19:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19115">magicwinmail-ftp-obtain-information(19115)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12388">12388</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110685011825461&amp;w=2">20050127 [SIG^2 G-TEC] Magic Winmail Server v4.0 Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1013017">1013017</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14053">14053</vuln:reference>
        </vuln:references>
        <vuln:summary>The FTP service in Magic Winmail Server 4.0 Build 1112 does not verify that the IP address in a PORT command is the same as the IP address of the user of the FTP session, which allows remote authenticated users to use the server as an intermediary for port scanning.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0316">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:webwasher:webwasher_classic:2.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:webwasher:webwasher_classic:3.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:webwasher:webwasher_classic:3.3</vuln:product>
            <vuln:product>cpe:/a:webwasher:webwasher_classic:2.2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0316</vuln:cve-id>
        <vuln:published-datetime>2005-01-28T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:56.477-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T17:39:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12394">12394</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14058">14058</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19144">webwasher-classic-connect-gain-access(19144)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.oliverkarow.de/research/WebWasherCONNECT.txt">http://www.oliverkarow.de/research/WebWasherCONNECT.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110693045507245&amp;w=2">20050128 WebWasher Classic - HTTP CONNECT weakness</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1013036">1013036</vuln:reference>
        </vuln:references>
        <vuln:summary>WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote attackers to bypass intended access restrictions.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0317">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:alt-n:webadmin:3.0.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:alt-n:webadmin:3.0.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0317</vuln:cve-id>
        <vuln:published-datetime>2005-01-28T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:56.633-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T17:43:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19161">webadmin-usereditaccountwdm-xss(19161)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12395">12395</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110692897003614&amp;w=2">20050128 Multiple vulnerabilities in Alt-N WebAdmin &lt;= 3.0.2</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1013038">1013038</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14079">14079</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in useredit_account.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the user parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0318">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:alt-n:webadmin:3.0.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:alt-n:webadmin:3.0.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0318</vuln:cve-id>
        <vuln:published-datetime>2005-01-28T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:56.790-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T17:44:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12395">12395</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1013038">1013038</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110692897003614&amp;w=2">20050128 Multiple vulnerabilities in Alt-N WebAdmin &lt;= 3.0.2</vuln:reference>
        </vuln:references>
        <vuln:summary>useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users' account information via a modified user parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0319">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:alt-n:webadmin:3.0.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:alt-n:webadmin:3.0.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0319</vuln:cve-id>
        <vuln:published-datetime>2005-01-28T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:56.963-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T17:57:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12395">12395</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19162">webadmin-html-injection(19162)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110692897003614&amp;w=2">20050128 Multiple vulnerabilities in Alt-N WebAdmin &lt;= 3.0.2</vuln:reference>
        </vuln:references>
        <vuln:summary>Direct remote injection vulnerability in modalfram.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to load external webpages that appear to come from the WebAdmin server, which allows remote attackers to inject arbitrary HTML or web script to facilitate cross-site scripting (XSS) and phishing attacks.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0320">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:icewarp:web_mail:5.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:icewarp:web_mail:5.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0320</vuln:cve-id>
        <vuln:published-datetime>2005-01-28T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:57.117-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T18:10:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12396">12396</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19147">merak-icewarp-multiple-xss(19147)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110693950205007&amp;w=2">20050128 Multiple vulnerabilities in Icewarp Web Mail 5.3.0: New holes</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to login.html, (2) accountid parameter to accountsettings_add.html, or the (3) note, (4) title, and (5) location fields to calendar.html.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0104">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.10" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.11" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.5" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.6" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.7" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.8" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.9" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.0" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.2" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3_rc1" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3a" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.44" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.0</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.0.5</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.0.4</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.1</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.2</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3_rc1</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.8</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.7</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.9</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.4</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.3</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.10</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.6</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3a</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.11</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.5</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.44</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.0</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.2</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0104</vuln:cve-id>
        <vuln:published-datetime>2005-01-29T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:19.807-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T02:41:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.squirrelmail.org/security/issue/2005-01-20">http://www.squirrelmail.org/security/issue/2005-01-20</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-135.html">RHSA-2005:135</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-099.html">RHSA-2005:099</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-662">DSA-662</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14096">14096</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13962/">13962</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2">20050129 SquirrelMail Security Advisory</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19036">squirrelmail-webmailphp-xss(19036)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml">GLSA-200501-39</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to inject arbitrary web script or HTML via certain integer variables.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0075">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.10" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.11" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.5" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.6" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.7" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.8" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.9" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.0" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.2" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3" />
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3a" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.0</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.0.5</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.0.4</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.1</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.2</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.8</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.7</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.9</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.4</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.3</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.10</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.6</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3a</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.11</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.5</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.0</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.2</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4</vuln:product>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0075</vuln:cve-id>
        <vuln:published-datetime>2005-01-29T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:14.557-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T10:16:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.squirrelmail.org/security/issue/2005-01-14">http://www.squirrelmail.org/security/issue/2005-01-14</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-135.html">RHSA-2005:135</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-099.html">RHSA-2005:099</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13962/">13962</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2">20050129 SquirrelMail Security Advisory</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml">GLSA-200501-39</vuln:reference>
        </vuln:references>
        <vuln:summary>prefs.php in SquirrelMail before 1.4.4, with register_globals enabled, allows remote attackers to inject local code into the SquirrelMail code via custom preference handlers.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0224">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:hp:virtualvault:4.5" />
                <cpe-lang:fact-ref name="cpe:/a:hp:virtualvault:4.6" />
                <cpe-lang:fact-ref name="cpe:/a:hp:virtualvault:4.7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:hp:virtualvault:4.6</vuln:product>
            <vuln:product>cpe:/a:hp:virtualvault:4.5</vuln:product>
            <vuln:product>cpe:/a:hp:virtualvault:4.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0224</vuln:cve-id>
        <vuln:published-datetime>2005-01-31T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:40.493-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T10:46:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14082/">14082</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110726808700080&amp;w=2">SSRT5900</vuln:reference>
        </vuln:references>
        <vuln:summary>Unknown vulnerability in HP-UX B.11.04 running Virtualvault 4.5 through 4.7, when running the TGA daemon, allows remote attackers to cause a denial of service via certain network traffic.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0245">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2.5" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2.6" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2.7" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.2" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.3" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.4" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.5" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.6" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.7" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.8" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.9" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.2" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.3" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.4" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.5" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.6" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.7" />
                <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:postgresql:postgresql:7.2.7</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.2.6</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.2.5</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.4.1</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.4.2</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.4.3</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.4.4</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.4.5</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.4.6</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.4.7</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.2.4</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.4</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.3</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.2.3</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.2.2</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.2</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.2.1</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.3.3</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.3.2</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.3.1</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:8.0</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.3.9</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.3.8</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.3.7</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.3.6</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.3.5</vuln:product>
            <vuln:product>cpe:/a:postgresql:postgresql:7.3.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0245</vuln:cve-id>
        <vuln:published-datetime>2005-02-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:35:11.523-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T12:41:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19188">postgresql-cursor-bo(19188)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-150.html">RHSA-2005:150</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-138.html">RHSA-2005:138</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/12948">12948</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-683">DSA-683</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110806034116082&amp;w=2">20050210 [USN-79-1] PostgreSQL vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.postgresql.org/pgsql-patches/2005-01/msg00216.php">[pgsql-patches] 20050120 Re: WIP: pl/pgsql cleanup</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.postgresql.org/pgsql-committers/2005-02/msg00049.php">[pgsql-committers] 20050207 pgsql: Prevent 4 more buffer overruns in the PL/PgSQL parser.</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.postgresql.org/pgsql-committers/2005-01/msg00298.php">[pgsql-committers] 20050121 pgsql: Prevent overrunning a heap-allocated buffer is more than 1024</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12417">12417</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which leads to a heap-based buffer overflow, a different vulnerability than CVE-2005-0247.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0101">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:newspost:newspost:2.1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:newspost:newspost:2.1.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0101</vuln:cve-id>
        <vuln:published-datetime>2005-02-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:19.277-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T02:00:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200502-05.xml">GLSA-200502-05</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19178">newspost-socketgetline-bo(19178)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vuxml.org/freebsd/7f13607b-6948-11d9-8937-00065be4b5b6.html">http://www.vuxml.org/freebsd/7f13607b-6948-11d9-8937-00065be4b5b6.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14092/">14092</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://people.freebsd.org/~niels/issues/newspost-20050114.txt">http://people.freebsd.org/~niels/issues/newspost-20050114.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746336728781&amp;w=2">20050202 RE: SECURITEY.NNOV.RU NewsPost buffer overflow [EXPLOIT]</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12418">12418</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1013056">1013056</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14098">14098</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the socket_getline function in Newspost 2.1.1 and earlier allows remote malicious NNTP servers to execute arbitrary code via a long string without a newline character.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0152">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0152</vuln:cve-id>
        <vuln:published-datetime>2005-02-02T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:27.760-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T12:50:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/203214">VU#203214</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-662">DSA-662</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14096">14096</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."</vuln:summary>
    </entry>
    <entry id="CVE-2005-0226">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ngircd:ngircd:0.8.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ngircd:ngircd:0.8.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0226</vuln:cve-id>
        <vuln:published-datetime>2005-02-03T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:41.400-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T11:00:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.nosystem.com.ar/advisories/advisory-11.txt">http://www.nosystem.com.ar/advisories/advisory-11.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14114/">14114</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746413108183&amp;w=2">20050203 ngIRCd &lt;= v0.8.2 Format String Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12434">12434</vuln:reference>
        </vuln:references>
        <vuln:summary>Format string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to SYSLOG, and with DEBUG enabled, allows remote attackers to execute arbitrary code.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0231">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0231</vuln:cve-id>
        <vuln:published-datetime>2005-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:35:10.117-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.6</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T11:09:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:100032" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100032" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=280056">https://bugzilla.mozilla.org/show_bug.cgi?id=280056</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19264">mozilla-firefox-tab-gain-access(19264)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_16_mozilla_firefox.html">SUSE-SA:2005:016</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/mfsa2005-26.html">http://www.mozilla.org/security/announce/mfsa2005-26.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mikx.de/firetabbing/">http://www.mikx.de/firetabbing/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110781134617144&amp;w=2">20050207 Firetabbing [Firefox 1.0]</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</vuln:reference>
        </vuln:references>
        <vuln:summary>Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."</vuln:summary>
    </entry>
    <entry id="CVE-2005-0156">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.0" />
                <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.1" />
                <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.3" />
                <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.4" />
                <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.4.2" />
                <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.4.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.4.3" />
                <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.4.4" />
                <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.4.5" />
                <cpe-lang:fact-ref name="cpe:/a:sgi:propack:3.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.3" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::workstation_server" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:3.0" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:fedora_core:core_3.0" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.0" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.0::i386" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.1" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.2" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.0" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.0::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.1" />
                <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.2" />
                <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:1.5" />
                <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:2.0" />
                <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:2.1" />
                <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:2.2" />
                <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:4.1::ia64" />
                <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:4.1::ppc" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:suse:suse_linux:8.2</vuln:product>
            <vuln:product>cpe:/o:suse:suse_linux:8.1</vuln:product>
            <vuln:product>cpe:/a:larry_wall:perl:5.8.4.3</vuln:product>
            <vuln:product>cpe:/a:larry_wall:perl:5.8.4.4</vuln:product>
            <vuln:product>cpe:/o:trustix:secure_linux:2.0</vuln:product>
            <vuln:product>cpe:/a:larry_wall:perl:5.8.4.5</vuln:product>
            <vuln:product>cpe:/o:trustix:secure_linux:2.2</vuln:product>
            <vuln:product>cpe:/o:trustix:secure_linux:2.1</vuln:product>
            <vuln:product>cpe:/o:trustix:secure_linux:1.5</vuln:product>
            <vuln:product>cpe:/a:larry_wall:perl:5.8.4.2.3</vuln:product>
            <vuln:product>cpe:/a:larry_wall:perl:5.8.4.2</vuln:product>
            <vuln:product>cpe:/a:larry_wall:perl:5.8.4.1</vuln:product>
            <vuln:product>cpe:/o:suse:suse_linux:8.0</vuln:product>
            <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::advanced_server</vuln:product>
            <vuln:product>cpe:/o:ubuntu:ubuntu_linux:4.1::ppc</vuln:product>
            <vuln:product>cpe:/o:ubuntu:ubuntu_linux:4.1::ia64</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:5.3</vuln:product>
            <vuln:product>cpe:/o:suse:suse_linux:8.0::i386</vuln:product>
            <vuln:product>cpe:/a:sgi:propack:3.0</vuln:product>
            <vuln:product>cpe:/o:redhat:fedora_core:core_3.0</vuln:product>
            <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::enterprise_server</vuln:product>
            <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::workstation_server</vuln:product>
            <vuln:product>cpe:/a:larry_wall:perl:5.8.4</vuln:product>
            <vuln:product>cpe:/a:larry_wall:perl:5.8.3</vuln:product>
            <vuln:product>cpe:/a:larry_wall:perl:5.8.1</vuln:product>
            <vuln:product>cpe:/a:larry_wall:perl:5.8.0</vuln:product>
            <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:3.0</vuln:product>
            <vuln:product>cpe:/o:suse:suse_linux:9.0</vuln:product>
            <vuln:product>cpe:/o:suse:suse_linux:9.0::x86_64</vuln:product>
            <vuln:product>cpe:/o:suse:suse_linux:9.1</vuln:product>
            <vuln:product>cpe:/o:suse:suse_linux:9.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0156</vuln:cve-id>
        <vuln:published-datetime>2005-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:35:03.383-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T13:02:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19208">perl-perliodebug-bo(19208)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2005/0003/">2005-0003</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12426">12426</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-105.html">RHSA-2005:105</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-103.html">RHSA-2005:103</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200502-13.xml">GLSA-200502-13</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.digitalmunition.com/DMA%5B2005-0131b%5D.txt">http://www.digitalmunition.com/DMA[2005-0131b].txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110779721503111&amp;w=2">20050207 DMA[2005-0131b] - 'Setuid Perl PERLIO_DEBUG</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110737149402683&amp;w=2">20050202 [USN-72-1] Perl vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:031">MDKSA-2005:031</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14120">14120</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152845</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=001056">CLSA-2006:1056</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0174">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable1" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable2" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable3" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable5" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable7" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable1" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable3" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable5" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable3" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:squid:squid:2.5.6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_stable9</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable3</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable2</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable5</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable1</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable7</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable5</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable3</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_stable3</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0174</vuln:cve-id>
        <vuln:published-datetime>2005-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:35:04.087-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T13:30:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/768702">VU#768702</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-header_parsing">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-header_parsing</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html">FEDORA-2005-373</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2">20050207 [USN-77-1] Squid vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931">CLA-2005:931</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12412">12412</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034">MDKSA-2005:034</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</vuln:reference>
        </vuln:references>
        <vuln:summary>Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0175">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable1" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable2" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable3" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable5" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable7" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable1" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable3" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable5" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable6" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable3" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable4" />
                <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:squid:squid:2.5.6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_stable9</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable3</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable2</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable5</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable1</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable6</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5.stable7</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable5</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable3</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_stable4</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_stable3</vuln:product>
            <vuln:product>cpe:/a:squid:squid:2.5_.stable1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0175</vuln:cve-id>
        <vuln:published-datetime>2005-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:35:04.147-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T13:42:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/625878">VU#625878</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-667">DSA-667</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2">20050207 [USN-77-1] Squid vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931">CLA-2005:931</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-response_splitting">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-response_splitting</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.squid-cache.org/Advisories/SQUID-2005_5.txt">http://www.squid-cache.org/Advisories/SQUID-2005_5.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html">FEDORA-2005-373</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12433">12433</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034">MDKSA-2005:034</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</vuln:reference>
        </vuln:references>
        <vuln:summary>Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0100">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:gnu:emacs:21.3" />
                <cpe-lang:fact-ref name="cpe:/a:gnu:emacs:20.0" />
                <cpe-lang:fact-ref name="cpe:/a:gnu:xemacs:21.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:gnu:xemacs:21.4</vuln:product>
            <vuln:product>cpe:/a:gnu:emacs:21.3</vuln:product>
            <vuln:product>cpe:/a:gnu:emacs:20.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0100</vuln:cve-id>
        <vuln:published-datetime>2005-02-07T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:34:57.040-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T01:40:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19246">xemacs-movemail-format-string(19246)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-133.html">RHSA-2005:133</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-112.html">RHSA-2005:112</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-110.html">RHSA-2005:110</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-685">DSA-685</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-671">DSA-671</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-670">DSA-670</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780416112719&amp;w=2">20050207 [USN-76-1] Emacs vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12462">12462</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/433928/30/5010/threaded">FLSA-2006:152898</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:038">MDKSA-2005:038</vuln:reference>
        </vuln:references>
        <vuln:summary>Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0249">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:3.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:3.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:3.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:3.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:3.1.5" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:3.1.6" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:1.0.1_build_8.01.434:mr3" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:1.0.1_build_8.01.437" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:1.0.1_build_8.01.446:mr4" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:1.0.1_build_8.01.457:mr5" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:1.0.1_build_8.01.460:mr6" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:1.0.1_build_8.01.464:mr7" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:1.0.1_build_8.01.471:mr8" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:1.1.1_mr1_build_8.1.1.314a" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:1.1.1_mr2_build_8.1.1.319" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:1.1.1_mr3_build_8.1.1.323" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:1.1.1_mr4_build_8.1.1.329" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:1.1.1_mr5_build_8.1.1.336" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:gateway_security:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:gateway_security:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:gateway_security:2.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.0::domino" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.1:build_458:exchange" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.1:build_459:exchange" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.1:build_461:exchange" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.5_build_719::exchange" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2.18_build_83::exchange" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2004::windows" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:8.01.434::corporate" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:8.01.437::corporate" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:8.01.446::corporate" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:8.01.457::corporate" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:8.01.460::corporate" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:8.01.464::corporate" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:8.01.471::corporate" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:8.1.1.319::corporate" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:8.1.1.323::corporate" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:8.1.1.329::corporate" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:8.1.1_build8.1.1.314a::corporate" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:9.0::macintosh_corporate" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2004::professional" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:norton_system_works:2004::windows" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:sav_filter_domino_nt_ports:build3.0.5::aix" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:sav_filter_domino_nt_ports:build3.0.5::os_400" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:sav_filter_for_domino_nt:3.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.59" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.60" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.61" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.62" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.63" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.67" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.68" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.0" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.0::bluecoat" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.0::netapp_filer" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.0::netapp_netcache" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.3" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.3.3::bluecoat" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.3.3::caching" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.3.3::filers" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.3.3::netapp_filer" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.3.3::netapp_netcache" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:brightmail_antispam:4.0" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:brightmail_antispam:5.5" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.0.2::smtp" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:9.0::macintosh_osx" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:3.0::macintosh" />
                <cpe-lang:fact-ref name="cpe:/a:symantec:norton_system_works:3.0::macintosh" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:symantec:web_security:3.01.63</vuln:product>
            <vuln:product>cpe:/a:symantec:web_security:3.01.62</vuln:product>
            <vuln:product>cpe:/a:symantec:web_security:3.01.61</vuln:product>
            <vuln:product>cpe:/a:symantec:web_security:3.01.68</vuln:product>
            <vuln:product>cpe:/a:symantec:client_security:1.1.1_mr5_build_8.1.1.336</vuln:product>
            <vuln:product>cpe:/a:symantec:web_security:3.01.67</vuln:product>
            <vuln:product>cpe:/a:symantec:norton_antivirus:8.01.460::corporate</vuln:product>
            <vuln:product>cpe:/a:symantec:mail_security:4.1:build_461:exchange</vuln:product>
            <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.3</vuln:product>
            <vuln:product>cpe:/a:symantec:client_security:1.0.1_build_8.01.457:mr5</vuln:product>
            <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.3.3::filers</vuln:product>
            <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.0</vuln:product>
            <vuln:product>cpe:/a:symantec:client_security:1.1.1_mr4_build_8.1.1.329</vuln:product>
            <vuln:product>cpe:/a:symantec:norton_antivirus:8.1.1.319::corporate</vuln:product>
            <vuln:product>cpe:/a:symantec:brightmail_antispam:4.0</vuln:product>
            <vuln:product>cpe:/a:symantec:norton_antivirus:8.01.434::corporate</vuln:product>
            <vuln:product>cpe:/a:symantec:web_security:3.01.60</vuln:product>
            <vuln:product>cpe:/a:symantec:norton_antivirus:9.0::macintosh_corporate</vuln:product>
            <vuln:product>cpe:/a:symantec:client_security:1.0.1_build_8.01.471:mr8</vuln:product>
            <vuln:product>cpe:/a:symantec:norton_antivirus:8.1.1.323::corporate</vuln:product>
            <vuln:product>cpe:/a:symantec:norton_antivirus:9.0::macintosh_osx</vuln:product>
            <vuln:product>cpe:/a:symantec:mail_security:4.5_build_719::exchange</vuln:product>
            <vuln:product>cpe:/a:symantec:brightmail_antispam:5.5</vuln:product>
            <vuln:product>cpe:/a:symantec:norton_antivirus:8.01.446::corporate</vuln:product>
            <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.3.3::caching</vuln:product>
            <vuln:product>cpe:/a:symantec:client_security:1.0.1_build_8.01.437</vuln:product>
            <vuln:product>cpe:/a:symantec:norton_system_works:2004::windows</vuln:product>
            <vuln:product>cpe:/a:symantec:sav_filter_for_domino_nt:3.1.1</vuln:product>
            <vuln:product>cpe:/a:symantec:sav_filter_domino_nt_ports:build3.0.5::os_400</vuln:product>
            <vuln:product>cpe:/a:symantec:client_security:1.1.1_mr2_build_8.1.1.319</vuln:product>
            <vuln:product>cpe:/a:symantec:client_security:1.0.1_build_8.01.446:mr4</vuln:product>
            <vuln:product>cpe:/a:symantec:mail_security:4.0.2::smtp</vuln:product>
            <vuln:product>cpe:/a:symantec:norton_antivirus:8.1.1_build8.1.1.314a::corporate</vuln:product>
            <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.0::netapp_netcache</vuln:product>
            <vuln:product>cpe:/a:symantec:client_security:1.1.1_mr1_build_8.1.1.314a</vuln:product>
            <vuln:product>cpe:/a:symantec:norton_antivirus:8.01.457::corporate</vuln:product>
            <vuln:product>cpe:/a:symantec:mail_security:4.1:build_459:exchange</vuln:product>
            <vuln:product>cpe:/a:symantec:norton_antivirus:2004::windows</vuln:product>
            <vuln:product>cpe:/a:symantec:norton_internet_security:3.0::macintosh</vuln:product>
            <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.3.3::netapp_filer</vuln:product>
            <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.3.3::netapp_netcache</vuln:product>
            <vuln:product>cpe:/a:symantec:client_security:1.0.1_build_8.01.464:mr7</vuln:product>
            <vuln:product>cpe:/a:symantec:norton_antivirus:8.1.1.329::corporate</vuln:product>
            <vuln:product>cpe:/a:symantec:norton_antivirus:8.01.471::corporate</vuln:product>
            <vuln:product>cpe:/a:symantec:web_security:3.01.59</vuln:product>
            <vuln:product>cpe:/a:symantec:mail_security:4.0::domino</vuln:product>
            <vuln:product>cpe:/a:symantec:client_security:1.0.1_build_8.01.434:mr3</vuln:product>
            <vuln:product>cpe:/a:symantec:gateway_security:2.0</vuln:product>
            <vuln:product>cpe:/a:symantec:client_security:1.1.1_mr3_build_8.1.1.323</vuln:product>
            <vuln:product>cpe:/a:symantec:sav_filter_domino_nt_ports:build3.0.5::aix</vuln:product>
            <vuln:product>cpe:/a:symantec:norton_internet_security:2004::professional</vuln:product>
            <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.0::bluecoat</vuln:product>
            <vuln:product>cpe:/a:symantec:gateway_security:2.0.1</vuln:product>
            <vuln:product>cpe:/a:symantec:gateway_security:1.0</vuln:product>
            <vuln:product>cpe:/a:symantec:client_security:1.0.1_build_8.01.460:mr6</vuln:product>
            <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.0::netapp_filer</vuln:product>
            <vuln:product>cpe:/a:symantec:norton_antivirus:8.01.437::corporate</vuln:product>
            <vuln:product>cpe:/a:symantec:norton_antivirus:8.01.464::corporate</vuln:product>
            <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.3.3::bluecoat</vuln:product>
            <vuln:product>cpe:/a:symantec:mail_security:4.1:build_458:exchange</vuln:product>
            <vuln:product>cpe:/a:symantec:antivirus_scan_engine:3.1.1</vuln:product>
            <vuln:product>cpe:/a:symantec:antivirus_scan_engine:3.1.2</vuln:product>
            <vuln:product>cpe:/a:symantec:antivirus_scan_engine:3.1.3</vuln:product>
            <vuln:product>cpe:/a:symantec:norton_system_works:3.0::macintosh</vuln:product>
            <vuln:product>cpe:/a:symantec:norton_antivirus:2.18_build_83::exchange</vuln:product>
            <vuln:product>cpe:/a:symantec:antivirus_scan_engine:3.1.4</vuln:product>
            <vuln:product>cpe:/a:symantec:antivirus_scan_engine:3.1.5</vuln:product>
            <vuln:product>cpe:/a:symantec:antivirus_scan_engine:3.1.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0249</vuln:cve-id>
        <vuln:published-datetime>2005-02-08T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:45.493-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T13:20:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/107822">VU#107822</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/18869">upx-engine-gain-control(18869)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>ISS</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/alerts/id/187">20050208 Symantec AntiVirus Library Heap Overflow</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.symantec.com/avcenter/security/Content/2005.02.08.html">http://www.symantec.com/avcenter/security/Content/2005.02.08.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1013133">1013133</vuln:reference>
        </vuln:references>
        <vuln:summary>Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0233">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:camino:0.8.5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.35" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.48" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.6" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.7" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.8" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.9" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0:rc1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0:rc2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.1:alpha" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.1:beta" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.2:alpha" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.2:beta" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4:alpha" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4:beta" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.6" />
                <cpe-lang:fact-ref name="cpe:/a:omnigroup:omniweb:5" />
                <cpe-lang:fact-ref name="cpe:/a:opera_software:opera_web_browser:7.54" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:mozilla:0.9.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:0.9.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:0.9.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:0.9.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:0.9.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.0:rc2</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.1:alpha</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.0:rc1</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.4:beta</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.0.2</vuln:product>
            <vuln:product>cpe:/a:omnigroup:omniweb:5</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.0.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:0.9.48</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.4:alpha</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.2:beta</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.0</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.2:alpha</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.3.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:0.9.4.1</vuln:product>
            <vuln:product>cpe:/a:opera_software:opera_web_browser:7.54</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.2.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.5.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:0.9.35</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:0.9.2.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.4.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.4.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:camino:0.8.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.4.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.1:beta</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:0.9.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:0.9.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:0.9.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0233</vuln:cve-id>
        <vuln:published-datetime>2005-02-08T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:35:10.493-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T11:35:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:100029" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100029" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19236">multiple-browsers-idn-spoof(19236)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_16_mozilla_firefox.html">SUSE-SA:2005:016</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/mfsa2005-29.html">http://www.mozilla.org/security/announce/mfsa2005-29.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.shmoo.com/idn/homograph.txt">http://www.shmoo.com/idn/homograph.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.shmoo.com/idn">http://www.shmoo.com/idn</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12461">12461</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782704923280&amp;w=2">20050208 International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs.</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html">20050206 state of homograph attacks</vuln:reference>
        </vuln:references>
        <vuln:summary>The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0367">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:argosoft:argosoft_mail_server:1.8.7.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:argosoft:argosoft_mail_server:1.8.7.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0367</vuln:cve-id>
        <vuln:published-datetime>2005-02-09T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:05.477-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T10:38:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110796956011699&amp;w=2">20050209 [SIG^2 G-TEC] ArGoSoft Mail Server Webmail Multiple Directory Traversal Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.security.org.sg/vuln/argosoftmail1873.html">http://www.security.org.sg/vuln/argosoftmail1873.html</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple directory traversal vulnerabilities in ArGoSoft Mail Server 1.8.7.3 allow remote authenticated users to read, delete, or upload arbitrary files via a .. (dot dot) in (1) the filename of an e-mail attachment, (2) the _msgatt.rec file, (3) and the /msg, /delete, /folderadd, and /folderdelete operations for the Folder parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0362">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:awstats:awstats:4.0" />
                <cpe-lang:fact-ref name="cpe:/a:awstats:awstats:5.0" />
                <cpe-lang:fact-ref name="cpe:/a:awstats:awstats:5.1" />
                <cpe-lang:fact-ref name="cpe:/a:awstats:awstats:5.2" />
                <cpe-lang:fact-ref name="cpe:/a:awstats:awstats:5.3" />
                <cpe-lang:fact-ref name="cpe:/a:awstats:awstats:5.4" />
                <cpe-lang:fact-ref name="cpe:/a:awstats:awstats:5.5" />
                <cpe-lang:fact-ref name="cpe:/a:awstats:awstats:5.7" />
                <cpe-lang:fact-ref name="cpe:/a:awstats:awstats:5.8" />
                <cpe-lang:fact-ref name="cpe:/a:awstats:awstats:5.9" />
                <cpe-lang:fact-ref name="cpe:/a:awstats:awstats:6.0" />
                <cpe-lang:fact-ref name="cpe:/a:awstats:awstats:6.1" />
                <cpe-lang:fact-ref name="cpe:/a:awstats:awstats:6.2" />
                <cpe-lang:fact-ref name="cpe:/a:awstats:awstats:6.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:awstats:awstats:4.0</vuln:product>
            <vuln:product>cpe:/a:awstats:awstats:5.5</vuln:product>
            <vuln:product>cpe:/a:awstats:awstats:5.8</vuln:product>
            <vuln:product>cpe:/a:awstats:awstats:5.7</vuln:product>
            <vuln:product>cpe:/a:awstats:awstats:5.9</vuln:product>
            <vuln:product>cpe:/a:awstats:awstats:6.0</vuln:product>
            <vuln:product>cpe:/a:awstats:awstats:6.1</vuln:product>
            <vuln:product>cpe:/a:awstats:awstats:5.0</vuln:product>
            <vuln:product>cpe:/a:awstats:awstats:6.2</vuln:product>
            <vuln:product>cpe:/a:awstats:awstats:6.3</vuln:product>
            <vuln:product>cpe:/a:awstats:awstats:5.2</vuln:product>
            <vuln:product>cpe:/a:awstats:awstats:5.1</vuln:product>
            <vuln:product>cpe:/a:awstats:awstats:5.4</vuln:product>
            <vuln:product>cpe:/a:awstats:awstats:5.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0362</vuln:cve-id>
        <vuln:published-datetime>2005-02-09T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:04.617-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T18:15:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=294488">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=294488</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/16089">16089</vuln:reference>
        </vuln:references>
        <vuln:summary>awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadplugin", or (3) "noloadplugin" parameters.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0364">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11" />
                <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.23::ia64_64-bit" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:hp:hp-ux:11.23::ia64_64-bit</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
            <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0364</vuln:cve-id>
        <vuln:published-datetime>2005-02-10T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-03-04T00:29:52.750-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T10:28:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:5690" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5690" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19276">hpux-bind-dos(19276)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14220/">14220</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110805105200470&amp;w=2">HPSBUX01117</vuln:reference>
        </vuln:references>
        <vuln:summary>Unknown vulnerability in BIND 9.2.0 in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to cause a denial of service.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0261">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2" />
                <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
            <vuln:product>cpe:/o:ibm:aix:5.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0261</vuln:cve-id>
        <vuln:published-datetime>2005-02-10T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:47.540-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T13:29:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67655&amp;apar=only">IY67655</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67457&amp;apar=only">IY67457</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19281">ibm-aix-ispath-information-disclosure(19281)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>IDEFENSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/application/poi/display?id=195&amp;type=vulnerabilities">20050210 IBM AIX lspath Local File Access Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12513">12513</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14232">14232</vuln:reference>
        </vuln:references>
        <vuln:summary>lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0074">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:xpcd:xpcd:2.08" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:xpcd:xpcd:2.08</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0074</vuln:cve-id>
        <vuln:published-datetime>2005-02-11T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:14.403-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-02T16:50:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-676">DSA-676</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12523">12523</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1013162">1013162</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14250">14250</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14248">14248</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in pcdsvgaview in xpcd 2.08 allows local users to execute arbitrary code.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0114">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:checkpoint:check_point_integrity_client:4.5.122.000" />
                <cpe-lang:fact-ref name="cpe:/a:zonelabs:zonealarm:5.5.062.011" />
                <cpe-lang:fact-ref name="cpe:/a:checkpoint:check_point_integrity_client:5.1.556.166" />
                <cpe-lang:fact-ref name="cpe:/a:zonelabs:zonealarm_wireless_security:5.5.080.000" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:checkpoint:check_point_integrity_client:4.5.122.000</vuln:product>
            <vuln:product>cpe:/a:zonelabs:zonealarm_wireless_security:5.5.080.000</vuln:product>
            <vuln:product>cpe:/a:checkpoint:check_point_integrity_client:5.1.556.166</vuln:product>
            <vuln:product>cpe:/a:zonelabs:zonealarm:5.5.062.011</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0114</vuln:cve-id>
        <vuln:published-datetime>2005-02-11T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:21.747-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T05:03:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>IDEFENSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/application/poi/display?id=199&amp;type=vulnerabilities">20050211 ZoneAlarm 5.1 Invalid Pointer Dereference Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://download.zonelabs.com/bin/free/securityAlert/19.html">http://download.zonelabs.com/bin/free/securityAlert/19.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12531">12531</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14256">14256</vuln:reference>
        </vuln:references>
        <vuln:summary>vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Client 4.x before 4.5.122.000 and 5.x before 5.1.556.166 do not properly verify that the ServerPortName argument to the NtConnectPort function is a valid memory address, which allows local users to cause a denial of service (system crash) when ZoneAlarm attempts to dereference an invalid pointer.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0430">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:id_software:quake_3_engine" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:id_software:quake_3_engine</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0430</vuln:cve-id>
        <vuln:published-datetime>2005-02-12T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:16.040-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T12:50:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://aluigi.altervista.org/adv/q3infoboom-adv.txt">http://aluigi.altervista.org/adv/q3infoboom-adv.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12534">12534</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110824822224025&amp;w=2">20050212 Infostring crash and shutdown in the Quake 3 engine</vuln:reference>
        </vuln:references>
        <vuln:summary>The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostring, possibly triggering a buffer overflow.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0406">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:image_processing_software:image_processing_software" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:image_processing_software:image_processing_software</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0406</vuln:cve-id>
        <vuln:published-datetime>2005-02-14T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:35:31.007-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T11:59:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redteam-pentesting.de/advisories/rt-sa-2005-008.txt">http://www.redteam-pentesting.de/advisories/rt-sa-2005-008.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://seclists.org/lists/fulldisclosure/2005/Feb/0343.html">20050214 Advisory: JPEG EXIF information disclosure</vuln:reference>
        </vuln:references>
        <vuln:summary>A design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an information leak of potentially sensitive visual information that had been removed from the main JPEG image.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0408">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:citrusdb:citrusdb:0.3.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:citrusdb:citrusdb:0.3.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0408</vuln:cve-id>
        <vuln:published-datetime>2005-02-14T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:35:31.147-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T12:09:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redteam-pentesting.de/advisories/rt-sa-2005-002.txt">http://www.redteam-pentesting.de/advisories/rt-sa-2005-002.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031707.html">20050214 Advisory: Authentication bypass in CitrusDB</vuln:reference>
        </vuln:references>
        <vuln:summary>CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass authentication and gain privileges by calculating the MD5 checksum of the user name combined with the "boogaadeeboo" string, which is hard-coded in the $hidden_hash variable.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0409">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:citrusdb:citrusdb:0.3.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:citrusdb:citrusdb:0.3.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0409</vuln:cve-id>
        <vuln:published-datetime>2005-02-14T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:35:31.227-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>6.4</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T12:16:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redteam-pentesting.de/advisories/rt-sa-2005-003.txt">http://www.redteam-pentesting.de/advisories/rt-sa-2005-003.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031707.html">20050214 Advisory: Upload Authorization bypass in CitrusDB</vuln:reference>
        </vuln:references>
        <vuln:summary>CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0410">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:citrusdb:citrusdb:0.3.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:citrusdb:citrusdb:0.3.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0410</vuln:cve-id>
        <vuln:published-datetime>2005-02-14T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:35:31.290-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T12:26:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redteam-pentesting.de/advisories/rt-sa-2005-004.txt">http://www.redteam-pentesting.de/advisories/rt-sa-2005-004.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031709.html">20050214 Advisory: SQL-Injection in CitrusDB</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via the fields of a CSV file.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0411">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:citrusdb:citrusdb:0.3.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:citrusdb:citrusdb:0.3.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0411</vuln:cve-id>
        <vuln:published-datetime>2005-02-14T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:35:31.353-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T12:37:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redteam-pentesting.de/advisories/rt-sa-2005-005.txt">http://www.redteam-pentesting.de/advisories/rt-sa-2005-005.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031710.html">20050214 Advisory: Directory traversal in CitrusDB</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary PHP files via .. (dot dot) sequences in the load parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0444">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:4.5.2_build_8848:r4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:vmware:workstation:4.5.2_build_8848:r4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0444</vuln:cve-id>
        <vuln:published-datetime>2005-02-14T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:18.557-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T13:46:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200502-18.xml">GLSA-200502-18</vuln:reference>
        </vuln:references>
        <vuln:summary>VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable temporary directory, which allows local users to execute arbitrary code.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0447">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:7.0</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0447</vuln:cve-id>
        <vuln:published-datetime>2005-02-15T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:19.210-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T13:56:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14286">14286</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19331">solaris-arp-dos(19331)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12553">12553</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57673-1">57673</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1013179">1013179</vuln:reference>
        </vuln:references>
        <vuln:summary>Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (hang) via a flood of certain ARP packets.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0433">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.0" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_beta1" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_final" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_rc1" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_rc2" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_rc3" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.6" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.7" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.9" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:7.0" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:7.0_final" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:7.1" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:7.2" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:7.3" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:7.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.9</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:7.6</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.6</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.7</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_final</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:7.3</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_rc2</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:7.2</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.0</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_rc3</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:7.1</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_rc1</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:7.0</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:7.0_final</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_beta1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0433</vuln:cve-id>
        <vuln:published-datetime>2005-02-15T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:16.523-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T13:02:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19344">phpnuke-multiple-scripts-path-disclosure(19344)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.waraxe.us/advisory-40.html">http://www.waraxe.us/advisory-40.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12561">12561</vuln:reference>
        </vuln:references>
        <vuln:summary>Php-Nuke 7.5 allows remote attackers to determine the full path of the web server via invalid or missing arguments to (1) db.php, (2) mainfile.php, (3) Downloads/index.php, or (4) Web_Links/index.php, which lists the path in a PHP error message.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0434">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.0" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_beta1" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_final" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_rc1" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_rc2" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.5_rc3" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.6" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.7" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:6.9" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:7.0" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:7.0_final" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:7.1" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:7.2" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:7.3" />
                <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:7.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.9</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:7.6</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.6</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.7</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_final</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:7.3</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_rc2</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:7.2</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.0</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_rc3</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:7.1</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_rc1</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:7.0</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:7.0_final</vuln:product>
            <vuln:product>cpe:/a:francisco_burzi:php-nuke:6.5_beta1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0434</vuln:cve-id>
        <vuln:published-datetime>2005-02-15T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:16.727-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T13:18:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19346">phpnuke-downloads-weblinks-xss(19346)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.waraxe.us/advisory-40.html">http://www.waraxe.us/advisory-40.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12561">12561</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 7.5 allow remote attackers to inject arbitrary HTML or web script via (1) the newdownloadshowdays parameter in a NewDownloads operation or (2) the newlinkshowdays parameter in a NewLinks operation.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0176">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:2.6.20" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:2.6.20</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0176</vuln:cve-id>
        <vuln:published-datetime>2005-02-15T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:35:04.227-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T13:52:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1225" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1225" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846102231365&amp;w=2">20050215 [USN-82-1] Linux kernel vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930">CLA-2005:930</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12598">12598</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-472.html">RHSA-2005:472</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19607">19607</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U">20060402-01-U</vuln:reference>
        </vuln:references>
        <vuln:summary>The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0149">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7:alpha" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7:beta" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7:rc1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7:rc2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7:rc3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.6" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:thunderbird:0.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:thunderbird:0.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:thunderbird:0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.7:rc1</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.7:rc2</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.7.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.7:rc3</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.7.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.7:alpha</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.7.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:mozilla:1.7:beta</vuln:product>
            <vuln:product>cpe:/a:mozilla:thunderbird:0.7.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:thunderbird:0.7.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:thunderbird:0.7.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0149</vuln:cve-id>
        <vuln:published-datetime>2005-02-15T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:35:02.947-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T12:36:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:100047" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100047" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=268107">https://bugzilla.mozilla.org/show_bug.cgi?id=268107</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19172">mozilla-cookie-policy-bypass(19172)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-335.html">RHSA-2005:335</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-323.html">RHSA-2005:323</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-094.html">RHSA-2005:094</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/mfsa2005-11.html">http://www.mozilla.org/security/announce/mfsa2005-11.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12407">12407</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19823">19823</vuln:reference>
        </vuln:references>
        <vuln:summary>Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers bypass the user's intended privacy and security policy by using cookies in e-mail messages.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0105">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:typespeed:typespeed:0.4.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:typespeed:typespeed:0.4.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0105</vuln:cve-id>
        <vuln:published-datetime>2005-02-16T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:20.010-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T03:11:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-684">DSA-684</vuln:reference>
        </vuln:references>
        <vuln:summary>Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0452">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:microsoft:asp.net:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:asp.net:1.0:sp1" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:asp.net:1.0:sp2" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:asp.net:1.1" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:asp.net:1.1:sp1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:asp.net:1.1:sp1</vuln:product>
            <vuln:product>cpe:/a:microsoft:asp.net:1.0</vuln:product>
            <vuln:product>cpe:/a:microsoft:asp.net:1.1</vuln:product>
            <vuln:product>cpe:/a:microsoft:asp.net:1.0:sp1</vuln:product>
            <vuln:product>cpe:/a:microsoft:asp.net:1.0:sp2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0452</vuln:cve-id>
        <vuln:published-datetime>2005-02-16T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:20.100-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T14:17:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12574">12574</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14214">14214</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110867912714913&amp;w=2">20050217 XSS vulnerabilty in ASP.Net [with details]</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml">http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "&lt;".</vuln:summary>
    </entry>
    <entry id="CVE-2005-0453">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:lighttpd:lighttpd:1.3.7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:lighttpd:lighttpd:1.3.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0453</vuln:cve-id>
        <vuln:published-datetime>2005-02-16T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:20.257-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T14:22:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200502-21.xml">GLSA-200502-21</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14297">14297</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://article.gmane.org/gmane.comp.web.lighttpd/1171">http://article.gmane.org/gmane.comp.web.lighttpd/1171</vuln:reference>
        </vuln:references>
        <vuln:summary>The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCGI scripts via a URL with a %00 (null) character after the file extension.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0462">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mercuryboard:mercuryboard:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:mercuryboard:mercuryboard:1.1" />
                <cpe-lang:fact-ref name="cpe:/a:mercuryboard:mercuryboard:1.1.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mercuryboard:mercuryboard:1.0</vuln:product>
            <vuln:product>cpe:/a:mercuryboard:mercuryboard:1.1</vuln:product>
            <vuln:product>cpe:/a:mercuryboard:mercuryboard:1.1.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0462</vuln:cve-id>
        <vuln:published-datetime>2005-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:21.960-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T14:57:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13937">13937</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lostmon.blogspot.com/2005/02/mercuryboard-forumphp-f-variable-xss.html">http://lostmon.blogspot.com/2005/02/mercuryboard-forumphp-f-variable-xss.html</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0243">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.5" />
                <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.6" />
                <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.6.0.1351" />
                <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:6.0" />
                <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:6.0.0.1750" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:yahoo:messenger:5.6.0.1351</vuln:product>
            <vuln:product>cpe:/a:yahoo:messenger:6.0.0.1750</vuln:product>
            <vuln:product>cpe:/a:yahoo:messenger:5.6</vuln:product>
            <vuln:product>cpe:/a:yahoo:messenger:6.0</vuln:product>
            <vuln:product>cpe:/a:yahoo:messenger:5.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0243</vuln:cve-id>
        <vuln:published-datetime>2005-02-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:44.277-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T12:22:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/secunia_research/2005-2/advisory/">http://secunia.com/secunia_research/2005-2/advisory/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13712">13712</vuln:reference>
        </vuln:references>
        <vuln:summary>Yahoo! Messenger 6.0.0.1750, and possibly other versions before 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote attackers to trick users into downloading and executing programs via file names containing a large number of spaces and multiple file extensions.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0242">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.5" />
                <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.6" />
                <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.6.0.1351" />
                <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:6.0" />
                <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:6.0.0.1750" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:yahoo:messenger:5.6.0.1351</vuln:product>
            <vuln:product>cpe:/a:yahoo:messenger:6.0.0.1750</vuln:product>
            <vuln:product>cpe:/a:yahoo:messenger:5.6</vuln:product>
            <vuln:product>cpe:/a:yahoo:messenger:6.0</vuln:product>
            <vuln:product>cpe:/a:yahoo:messenger:5.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0242</vuln:cve-id>
        <vuln:published-datetime>2005-02-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:44.103-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-06T12:09:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/secunia_research/2004-6/advisory/">http://secunia.com/secunia_research/2004-6/advisory/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/11815">11815</vuln:reference>
        </vuln:references>
        <vuln:summary>The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0502">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:xinkaa_web_station:xinkaa_web_station:1.0.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:xinkaa_web_station:xinkaa_web_station:1.0.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0502</vuln:cve-id>
        <vuln:published-datetime>2005-02-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:28.883-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T16:16:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19404">xinkaa-web-directory-traversal(19404)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12606">12606</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2005/0189">ADV-2005-0189</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14349">14349</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://aluigi.altervista.org/adv/xinkaa-adv.txt">http://aluigi.altervista.org/adv/xinkaa-adv.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in Xinkaa 1.0.3 and earlier allows remote attackers to read arbitrary files via (1) ../ and (2) ..\ characters in an HTTP request.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0519">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:argosoft:ftp_server:1.4.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:argosoft:ftp_server:1.4.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:argosoft:ftp_server:1.4.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:argosoft:ftp_server:1.4.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:argosoft:ftp_server:1.4.1.5" />
                <cpe-lang:fact-ref name="cpe:/a:argosoft:ftp_server:1.4.1.6" />
                <cpe-lang:fact-ref name="cpe:/a:argosoft:ftp_server:1.4.1.7" />
                <cpe-lang:fact-ref name="cpe:/a:argosoft:ftp_server:1.4.1.8" />
                <cpe-lang:fact-ref name="cpe:/a:argosoft:ftp_server:1.4.1.9" />
                <cpe-lang:fact-ref name="cpe:/a:argosoft:ftp_server:1.4.2" />
                <cpe-lang:fact-ref name="cpe:/a:argosoft:ftp_server:1.4.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:argosoft:ftp_server:1.4.2.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:argosoft:ftp_server:1.4.1.7</vuln:product>
            <vuln:product>cpe:/a:argosoft:ftp_server:1.4.1.8</vuln:product>
            <vuln:product>cpe:/a:argosoft:ftp_server:1.4.1.9</vuln:product>
            <vuln:product>cpe:/a:argosoft:ftp_server:1.4.1.3</vuln:product>
            <vuln:product>cpe:/a:argosoft:ftp_server:1.4.1.4</vuln:product>
            <vuln:product>cpe:/a:argosoft:ftp_server:1.4.1.5</vuln:product>
            <vuln:product>cpe:/a:argosoft:ftp_server:1.4.2.2</vuln:product>
            <vuln:product>cpe:/a:argosoft:ftp_server:1.4.1.6</vuln:product>
            <vuln:product>cpe:/a:argosoft:ftp_server:1.4.2.1</vuln:product>
            <vuln:product>cpe:/a:argosoft:ftp_server:1.4.2</vuln:product>
            <vuln:product>cpe:/a:argosoft:ftp_server:1.4.1.1</vuln:product>
            <vuln:product>cpe:/a:argosoft:ftp_server:1.4.1.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0519</vuln:cve-id>
        <vuln:published-datetime>2005-02-18T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:36:06.557-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T17:52:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.argosoft.com/ftpserver/changelist.aspx">http://www.argosoft.com/ftpserver/changelist.aspx</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14172">14172</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/17939">argosoft-ink-file-upload(17939)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12487">12487</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/13614">13614</vuln:reference>
        </vuln:references>
        <vuln:summary>ArGoSoft FTP Server before 1.4.2.7 allows remote attackers to read arbitrary files by uploading a ZIP file containing a shortcut (.LNK) file, using SITE UNZIP to extract the .LNK file onto the server, then accessing the file, a different vulnerability than CVE-2005-0520.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0513">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:pmachine:pmachine_pro:2.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:pmachine:pmachine_pro:2.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0513</vuln:cve-id>
        <vuln:published-datetime>2005-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:31.320-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T17:16:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12597">12597</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/15473">15473</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110883604531802&amp;w=2">20050219 pMachine Pro / pMachine Free Remote Code Execution</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and possibly other versions including pMachine Free, allows remote attackers to execute arbitrary PHP code by directly requesting mail_autocheck.php and modifying the pm_path parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2003-1086.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0495">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:zeroboard:zeroboard:4.1_pl2" />
                <cpe-lang:fact-ref name="cpe:/a:zeroboard:zeroboard:4.1_pl3" />
                <cpe-lang:fact-ref name="cpe:/a:zeroboard:zeroboard:4.1_pl4" />
                <cpe-lang:fact-ref name="cpe:/a:zeroboard:zeroboard:4.1_pl5" />
                <cpe-lang:fact-ref name="cpe:/a:zeroboard:zeroboard:4.1_pl6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:zeroboard:zeroboard:4.1_pl4</vuln:product>
            <vuln:product>cpe:/a:zeroboard:zeroboard:4.1_pl5</vuln:product>
            <vuln:product>cpe:/a:zeroboard:zeroboard:4.1_pl2</vuln:product>
            <vuln:product>cpe:/a:zeroboard:zeroboard:4.1_pl3</vuln:product>
            <vuln:product>cpe:/a:zeroboard:zeroboard:4.1_pl6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0495</vuln:cve-id>
        <vuln:published-datetime>2005-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:27.743-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T15:40:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19420">zeroboard-xss(19420)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1013243">1013243</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110884332105513&amp;w=2">20050219 Multiples vulnerability in ZeroBoard,</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in ZeroBoard allows remote attackers to inject arbitrary web script or HTML via the (1) sn1, (2) year, or (3) page parameter to zboard.php or (4) filename to view_image.php.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0092">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::workstation" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:4.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::enterprise_server</vuln:product>
            <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::workstation</vuln:product>
            <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::advanced_server</vuln:product>
            <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:4.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0092</vuln:cve-id>
        <vuln:published-datetime>2005-02-19T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:45:17.637-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-03T00:17:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12599">12599</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/20620">red-hat-patch-dos(20620)</vuln:reference>
        </vuln:references>
        <vuln:summary>Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when running on x86 with the hugemem kernel, allows local users to cause a denial of service (crash).</vuln:summary>
    </entry>
    <entry id="CVE-2005-0499">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:gigafast_ethernet:gigafast_router:ee400-r" />
                <cpe-lang:fact-ref name="cpe:/h:gigafast_ethernet:gigafast_router:ee410-r" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:gigafast_ethernet:gigafast_router:ee410-r</vuln:product>
            <vuln:product>cpe:/h:gigafast_ethernet:gigafast_router:ee400-r</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0499</vuln:cve-id>
        <vuln:published-datetime>2005-02-20T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:28.397-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T16:04:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19426">gigafast-dns-queries-dos(19426)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110900986022760&amp;w=2">20050220 Gigafast/CompUSA router (model EE400-R) vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:summary>Gigafast router (aka CompUSA router) with the DNS proxy option enabled allows remote attackers to cause a denial of service via malformed DNS queries.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0511">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:2.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:2.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:2.0_beta_2" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:2.0_beta_3" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:2.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:2.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:2.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:2.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:2.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:2.2.5" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:2.2.6" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:2.2.7" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:2.2.8" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:2.2.9_can" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:2.3.0" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:2.3.3" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:2.3.4" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.0.0" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.0.0_beta_2" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.0.0_can4" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.0.0_rc4" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.0_beta_2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:jelsoft:vbulletin:2.0_beta_3</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:2.2.9_can</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:2.0_beta_2</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:2.0</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:2.2.6</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:2.2.7</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:2.2.8</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:2.2.1</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:3.0.0_beta_2</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:2.2.0</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:2.2.3</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:3.0.0_rc4</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:2.2.2</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:2.2.5</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:2.2.4</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:3.0_beta_2</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:3.0.2</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:2.3.0</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:3.0.1</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:3.0.0</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:3.0.6</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:2.3.3</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:3.0.5</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:2.0.2</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:2.3.4</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:3.0.4</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:2.0.1</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:3.0.3</vuln:product>
            <vuln:product>cpe:/a:jelsoft:vbulletin:3.0.0_can4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0511</vuln:cve-id>
        <vuln:published-datetime>2005-02-21T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:30.947-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T16:25:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14326">14326</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vbulletin.com/forum/showthread.php?postid=819562">http://www.vbulletin.com/forum/showthread.php?postid=819562</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12622">12622</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910899415763&amp;w=2">20050222 [SCAN Associates Security Advisory] vbulletin 3.0.6 and below php code injection</vuln:reference>
        </vuln:references>
        <vuln:summary>misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0512">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mambo:mambo:4.5.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mambo:mambo:4.5.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0512</vuln:cve-id>
        <vuln:published-datetime>2005-02-21T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:31.163-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T17:13:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14337">14337</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://mamboforge.net/frs/download.php/4043/Patch_4.5.2_to_4.5.2.1.zip">http://mamboforge.net/frs/download.php/4043/Patch_4.5.2_to_4.5.2.1.zip</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file inclusion vulnerability in Tar.php in Mambo 4.5.2 allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2004-1693.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0503">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:uim:uim:0.4.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.1" />
                <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.1::x86_64" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:uim:uim:0.4.5</vuln:product>
            <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:10.1</vuln:product>
            <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:10.1::x86_64</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0503</vuln:cve-id>
        <vuln:published-datetime>2005-02-21T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T15:36:04.197-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T16:43:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12604">12604</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/13981">13981</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.freedesktop.org/archives/uim/2005-February/000996.html">[uim] 20050220 uim 0.4.5.1 released</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:046">MDKSA-2005:046</vuln:reference>
        </vuln:references>
        <vuln:summary>uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0496">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:knox_software:arkeia:4.0" />
                <cpe-lang:fact-ref name="cpe:/a:knox_software:arkeia:4.1" />
                <cpe-lang:fact-ref name="cpe:/a:knox_software:arkeia:4.2" />
                <cpe-lang:fact-ref name="cpe:/a:knox_software:arkeia:5.2" />
                <cpe-lang:fact-ref name="cpe:/a:knox_software:arkeia:5.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:knox_software:arkeia:5.3</vuln:product>
            <vuln:product>cpe:/a:knox_software:arkeia:5.2</vuln:product>
            <vuln:product>cpe:/a:knox_software:arkeia:4.0</vuln:product>
            <vuln:product>cpe:/a:knox_software:arkeia:4.2</vuln:product>
            <vuln:product>cpe:/a:knox_software:arkeia:4.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0496</vuln:cve-id>
        <vuln:published-datetime>2005-02-21T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:27.913-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T15:54:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/20667">arkeia-backup-client-gain-access(20667)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1013256">1013256</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://metasploit.com/research/arkeia_agent/">http://metasploit.com/research/arkeia_agent/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110900879826004&amp;w=2">20050220 Arkeia Network Backup Client Remote Access</vuln:reference>
        </vuln:references>
        <vuln:summary>Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0467">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:putty:putty:0.56" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:putty:putty:0.56</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0467</vuln:cve-id>
        <vuln:published-datetime>2005-02-21T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:22.850-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-07T15:11:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>IDEFENSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.idefense.com/application/poi/display?id=201&amp;type=vulnerabilities">20050221 Multiple PuTTY SFTP Client Packet Parsing Integer Overflow Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200502-28.xml">GLSA-200502-28</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14333">14333</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19403">putty-sftppktgetstring-bo(19403)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-string.html">http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-string.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-readdir.html">http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-readdir.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002416">http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002416</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002414">http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002414</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17214">17214</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after insufficient memory has been allocated.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0494">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:thomson:thomson_cable_modem:tcw690" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:thomson:thomson_cable_modem:tcw690</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0494</vuln:cve-id>
        <vuln:published-datetime>2005-02-21T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T16:46:27.587-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:a