<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" xmlns:patch="http://scap.nist.gov/schema/patch/0.1" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/0.1" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" nvd_xml_version="2.0" pub_date="2013-05-23T09:02:09" xsi:schemaLocation="http://scap.nist.gov/schema/patch/0.1 http://nvd.nist.gov/schema/patch_0.1.xsd http://scap.nist.gov/schema/scap-core/0.1 http://nvd.nist.gov/schema/scap-core_0.1.xsd http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
  <entry id="CVE-2005-0001">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:2.6.20"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::workstation_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:2"/>
        <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::workstation_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:4.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.28</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:2.6.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
      <vuln:product>cpe:/o:trustix:secure_linux:2.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.5</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::advanced_server</vuln:product>
      <vuln:product>cpe:/o:trustix:secure_linux:2.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.24</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::advanced_server</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
      <vuln:product>cpe:/o:trustix:secure_linux:2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:3.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0001</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:19.967-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity approximated="true">MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T14:09:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10322" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10322" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://bugzilla.fedora.us/show_bug.cgi?id=2336" xml:lang="en">FLSA:2336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18849" xml:lang="en">linux-fault-handler-gain-privileges(18849)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2005/0001/" xml:lang="en">2005-0001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12244" xml:lang="en">12244</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-092.html" xml:lang="en">RHSA-2005:092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-043.html" xml:lang="en">RHSA-2005:043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-017.html" xml:lang="en">RHSA-2005:017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-016.html" xml:lang="en">RHSA-2005:016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1082" xml:lang="en">DSA-1082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1070" xml:lang="en">DSA-1070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1069" xml:lang="en">DSA-1069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1067" xml:lang="en">DSA-1067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012862" xml:lang="en">1012862</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20338" xml:lang="en">20338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20202" xml:lang="en">20202</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20163" xml:lang="en">20163</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13822" xml:lang="en">13822</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110581146702951&amp;w=2" xml:lang="en">20050114 [USN-60-0] Linux kernel vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110554694522719&amp;w=2" xml:lang="en">20050112 Linux kernel i386 SMP page fault handler privilege escalation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030826.html" xml:lang="en">20050112 Linux kernel i386 SMP page fault handler privilege escalation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isec.pl/vulnerabilities/isec-0022-pagefault.txt" xml:lang="en">http://isec.pl/vulnerabilities/isec-0022-pagefault.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" xml:lang="en">CLA-2005:930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" xml:lang="en">MDKSA-2005:022</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10322" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10322" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Race condition in the page fault handler (fault.c) for Linux kernel 2.2.x to 2.2.7, 2.4 to 2.4.29, and 2.6 to 2.6.10, when running on multiprocessor machines, allows local users to execute arbitrary code via concurrent threads that share the same virtual memory space and simultaneously request stack expansion.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0002">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gentoo:poppassd_pam:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gentoo:poppassd_pam:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0002</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:43.210-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T14:05:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200501-22.xml" xml:lang="en">GLSA-200501-22</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012840" xml:lang="en">1012840</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13865" xml:lang="en">13865</vuln:reference>
    </vuln:references>
    <vuln:summary>poppassd_pam 1.0 and earlier, when changing a user password, does not verify that the user entered the old password correctly, which allows remote attackers to change passwords for arbitrary users.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0003">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:avaya:mn100"/>
        <cpe-lang:fact-ref name="cpe:/a:avaya:network_routing"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:converged_communications_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:s8710:r2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:s8710:r2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:avaya:modular_messaging_message_storage_server:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:avaya:modular_messaging_message_storage_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23:pre9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23_ow2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24_ow1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.29:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.29:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.0"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.0::amd64"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.1"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.1::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:9.2"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:9.2::amd64"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::advanced_servers"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:avaya:intuity_audix:::lx"/>
        <cpe-lang:fact-ref name="cpe:/a:mandrakesoft:mandrake_multi_network_firewall:8.2"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:s8300:r2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:s8300:r2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:s8500:r2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:s8500:r2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:s8700:r2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/h:avaya:s8700:r2.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:10.0::amd64</vuln:product>
      <vuln:product>cpe:/a:mandrakesoft:mandrake_multi_network_firewall:8.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre5</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.24_ow1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23:pre9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.29:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre3</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::workstation</vuln:product>
      <vuln:product>cpe:/h:avaya:s8500:r2.0.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre2</vuln:product>
      <vuln:product>cpe:/h:avaya:s8710:r2.0.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.29:rc2</vuln:product>
      <vuln:product>cpe:/o:avaya:modular_messaging_message_storage_server:2.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:9.2::amd64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18::x86</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23_ow2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
      <vuln:product>cpe:/a:avaya:network_routing</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test11</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:10.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::advanced_servers</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.24</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:10.1::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
      <vuln:product>cpe:/h:avaya:s8300:r2.0.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
      <vuln:product>cpe:/h:avaya:converged_communications_server:2.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre5</vuln:product>
      <vuln:product>cpe:/a:avaya:mn100</vuln:product>
      <vuln:product>cpe:/a:avaya:intuity_audix:::lx</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre2</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.22</vuln:product>
      <vuln:product>cpe:/h:avaya:s8700:r2.0.1</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:9.2</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:3.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21</vuln:product>
      <vuln:product>cpe:/o:avaya:modular_messaging_message_storage_server:1.1</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:10.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test6</vuln:product>
      <vuln:product>cpe:/h:avaya:s8500:r2.0.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
      <vuln:product>cpe:/h:avaya:s8710:r2.0.1</vuln:product>
      <vuln:product>cpe:/h:avaya:s8700:r2.0.0</vuln:product>
      <vuln:product>cpe:/h:avaya:s8300:r2.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0003</vuln:cve-id>
    <vuln:published-datetime>2005-04-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:20.187-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9512" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9512" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12261" xml:lang="en">12261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-043.html" xml:lang="en">RHSA-2005:043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18886" xml:lang="en">linux-vma-gain-privileges(18886)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2005/0001/" xml:lang="en">2005-0001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-017.html" xml:lang="en">RHSA-2005:017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" xml:lang="en">SUSE-SA:2005:018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1082" xml:lang="en">DSA-1082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1070" xml:lang="en">DSA-1070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1069" xml:lang="en">DSA-1069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1067" xml:lang="en">DSA-1067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012885" xml:lang="en">1012885</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20338" xml:lang="en">20338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20202" xml:lang="en">20202</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20163" xml:lang="en">20163</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://linux.bkbits.net:8080/linux-2.6/cset@41a6721cce-LoPqkzKXudYby_3TUmg" xml:lang="en">http://linux.bkbits.net:8080/linux-2.6/cset@41a6721cce-LoPqkzKXudYby_3TUmg</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://linux.bkbits.net:8080/linux-2.4/cset@41c36fb6q1Z68WUzKQFjJR-40Ev3tw" xml:lang="en">http://linux.bkbits.net:8080/linux-2.4/cset@41c36fb6q1Z68WUzKQFjJR-40Ev3tw</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" xml:lang="en">MDKSA-2005:022</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9512" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9512" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0004">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.11:gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.5a"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.7:gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.8:gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.0.9:gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.1.2:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.1.3:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:mysql:4.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::arm"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::hppa"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ia-32"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ia-64"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::m68k"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::mips"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::mipsel"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::s-390"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:fedora_core:core_1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:7.3::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:9.0::i386"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:linux:9.0::i386</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.15</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.8:gamma</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::mips</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.21</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.10</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ia-32</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::s-390</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::alpha</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.11:gamma</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::arm</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.9</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.12</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::mipsel</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.3</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.2</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.1.3</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.9:gamma</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.1.2:alpha</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ppc</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::hppa</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.4</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:7.3::i386</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.11</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.7</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.1.0:alpha</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::m68k</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.6</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.0</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.5a</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ia-64</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.18</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.7:gamma</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.20</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.1.4</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.1.0.0</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.1.3:beta</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.5</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.14</vuln:product>
      <vuln:product>cpe:/o:redhat:fedora_core:core_1.0</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::sparc</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.1.5</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.1</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.8</vuln:product>
      <vuln:product>cpe:/a:mysql:mysql:4.0.13</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0004</vuln:cve-id>
    <vuln:published-datetime>2005-04-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:44.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12277" xml:lang="en">12277</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-647" xml:lang="en">DSA-647</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13867" xml:lang="en">13867</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18922" xml:lang="en">mysql-mysqlaccess-symlink(18922)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://mysql.osuosl.org/doc/mysql/en/News-4.1.10.html" xml:lang="en">http://mysql.osuosl.org/doc/mysql/en/News-4.1.10.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608297217224&amp;w=2" xml:lang="en">20050118 [USN-63-1] MySQL client vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.mysql.com/internals/20600" xml:lang="en">http://lists.mysql.com/internals/20600</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000947" xml:lang="en">CLA-2005:947</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:036" xml:lang="en">MDKSA-2005:036</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1" xml:lang="en">101864</vuln:reference>
    </vuln:references>
    <vuln:summary>The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files via a symlink attack on temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0005">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:graphicsmagick:graphicsmagick:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:graphicsmagick:graphicsmagick:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:graphicsmagick:graphicsmagick:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:graphicsmagick:graphicsmagick:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:graphicsmagick:graphicsmagick:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:5.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:5.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:5.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.0.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::arm"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::hppa"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ia-32"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ia-64"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::m68k"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::mips"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::mipsel"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::s-390"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:0.7"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:1.1a"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:1.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:1.4:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:1.4:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.0::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.1"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.2"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.0::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.1"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::mips</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.2.0.4</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::s-390</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:3.0</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::alpha</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:0.5</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:5.3.3</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.0</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:1.4:rc3</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.1.7</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.0.4</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::mipsel</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.0.2</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.1.6</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.0.8</vuln:product>
      <vuln:product>cpe:/a:graphicsmagick:graphicsmagick:1.1</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::hppa</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:1.4:rc2</vuln:product>
      <vuln:product>cpe:/a:graphicsmagick:graphicsmagick:1.1.4</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.1.1.6</vuln:product>
      <vuln:product>cpe:/a:graphicsmagick:graphicsmagick:1.0.6</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:8.0::i386</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.0</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:8.2</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.1.4</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:5.4.7</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.2</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.0.2.5</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:1.2</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:1.4:rc1</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ia-32</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:8.1</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.0.5</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.0.1</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.2</vuln:product>
      <vuln:product>cpe:/a:graphicsmagick:graphicsmagick:1.0</vuln:product>
      <vuln:product>cpe:/a:graphicsmagick:graphicsmagick:1.1.3</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::arm</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:0.7</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.1</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.2.0.7</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ppc</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.1.3</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.0.6</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::m68k</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.1</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.0::x86_64</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:8.0</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.1.2</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ia-64</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.0.3</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.0.7</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:1.1a</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::sparc</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:1.4</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:5.4.3</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0005</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:20.497-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T14:36:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9925" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9925" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-071.html" xml:lang="en">RHSA-2005:071</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-646" xml:lang="en">DSA-646</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=184&amp;type=vulnerabilities" xml:lang="en">20050117 Multiple Vendor ImageMagick .psd Image File Decode Heap Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-37.xml" xml:lang="en">GLSA-200501-37</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608222117215&amp;w=2" xml:lang="en">20050118 [USN-62-1] imagemagick vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-070.html" xml:lang="en">RHSA-2005:070</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9925" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9925" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0006">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.8</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.6</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0006</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:20.937-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T14:11:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10801" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10801" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00017.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00017.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13946/" xml:lang="en">13946</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18999" xml:lang="en">ethereal-cops-dos(18999)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-037.html" xml:lang="en">RHSA-2005:037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml" xml:lang="en">GLSA-200501-27</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/p-106.shtml" xml:lang="en">P-106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12326" xml:lang="en">12326</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-011.html" xml:lang="en">RHSA-2005:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" xml:lang="en">FLSA-2006:152922</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013" xml:lang="en">MDKSA-2005:013</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10801" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10801" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The COPS dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (infinite loop).</vuln:summary>
  </entry>
  <entry id="CVE-2005-0007">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.8</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.6</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0007</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:21.060-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T14:20:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11381" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11381" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19000" xml:lang="en">ethereal-dlsw-dos(19000)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13946/" xml:lang="en">13946</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-037.html" xml:lang="en">RHSA-2005:037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml" xml:lang="en">GLSA-200501-27</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00017.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00017.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/p-106.shtml" xml:lang="en">P-106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12326" xml:lang="en">12326</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-011.html" xml:lang="en">RHSA-2005:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" xml:lang="en">FLSA-2006:152922</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013" xml:lang="en">MDKSA-2005:013</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11381" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11381" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unknown vulnerability in the DLSw dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (application crash from assertion).</vuln:summary>
  </entry>
  <entry id="CVE-2005-0008">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.8</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.6</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.5</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0008</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:21.187-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T14:18:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10689" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10689" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00017.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00017.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19001" xml:lang="en">ethereal-dnp-memory-corruption(19001)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-037.html" xml:lang="en">RHSA-2005:037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml" xml:lang="en">GLSA-200501-27</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/p-106.shtml" xml:lang="en">P-106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13946/" xml:lang="en">13946</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12326" xml:lang="en">12326</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-011.html" xml:lang="en">RHSA-2005:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" xml:lang="en">FLSA-2006:152922</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013" xml:lang="en">MDKSA-2005:013</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10689" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10689" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unknown vulnerability in the DNP dissector in Ethereal 0.10.5 through 0.10.8 allows remote attackers to cause "memory corruption."</vuln:summary>
  </entry>
  <entry id="CVE-2005-0009">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.8</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.6</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0009</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:21.310-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T14:21:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10623" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10623" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml" xml:lang="en">GLSA-200501-27</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13946/" xml:lang="en">13946</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19002" xml:lang="en">ethereal-gnutella-dos(19002)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-037.html" xml:lang="en">RHSA-2005:037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00017.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00017.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/p-106.shtml" xml:lang="en">P-106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12326" xml:lang="en">12326</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-011.html" xml:lang="en">RHSA-2005:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" xml:lang="en">FLSA-2006:152922</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013" xml:lang="en">MDKSA-2005:013</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10623" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10623" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unknown vulnerability in the Gnutella dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (application crash).</vuln:summary>
  </entry>
  <entry id="CVE-2005-0010">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.8</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.4</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.6</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.5</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0010</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:21.467-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T14:28:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9521" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9521" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19003" xml:lang="en">ethereal-mmse-free-memory(19003)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13946/" xml:lang="en">13946</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-037.html" xml:lang="en">RHSA-2005:037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml" xml:lang="en">GLSA-200501-27</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00017.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00017.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/p-106.shtml" xml:lang="en">P-106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12326" xml:lang="en">12326</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-011.html" xml:lang="en">RHSA-2005:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" xml:lang="en">FLSA-2006:152922</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013" xml:lang="en">MDKSA-2005:013</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9521" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9521" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unknown vulnerability in the MMSE dissector in Ethereal 0.10.4 through 0.10.8 allows remote attackers to cause a denial of service by triggering a free of statically allocated memory.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0011">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:kde:kde:3.3.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.3</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0011</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:05.077-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T14:24:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kde.org/info/security/advisory-20050215-1.txt" xml:lang="en">http://www.kde.org/info/security/advisory-20050215-1.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14306" xml:lang="en">14306</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2005-February/msg00044.html" xml:lang="en">FEDORA-2005-148</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200502-23.xml" xml:lang="en">GLSA-200502-23</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (INDI) in KDE 3.3 to 3.3.2, allow local users and remote attackers to execute arbitrary code via stack-based buffer overflows.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0012">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.7.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:dillo:dillo_web_browser:0.8.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.5.1</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.7</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.8.3</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.6.2</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.7.1</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.8.2</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.2.4</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.7.3</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.6</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.4</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.8.1</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.3.1</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.7.1.2</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.8</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.2.3</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.3</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.6.3</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.6.1</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.6.4</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.6.6</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.7.2</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.2</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.2.1</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.2.2</vuln:product>
      <vuln:product>cpe:/a:dillo:dillo_web_browser:0.6.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0012</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:05.247-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T14:27:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12203" xml:lang="en">12203</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18807" xml:lang="en">dillo-capi-format-string(18807)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-11.xml" xml:lang="en">GLSA-200501-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13760/" xml:lang="en">13760</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13764" xml:lang="en">13764</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in the a_Interface_msg function in Dillo before 0.8.3-r4 allows remote attackers to execute arbitrary code via format string specifiers in a web page.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0013">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ncpfs:ncpfs:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ncpfs:ncpfs:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ncpfs:ncpfs:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ncpfs:ncpfs:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ncpfs:ncpfs:2.2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ncpfs:ncpfs:2.2.1</vuln:product>
      <vuln:product>cpe:/a:ncpfs:ncpfs:2.2.4</vuln:product>
      <vuln:product>cpe:/a:ncpfs:ncpfs:2.2.3</vuln:product>
      <vuln:product>cpe:/a:ncpfs:ncpfs:2.2.2</vuln:product>
      <vuln:product>cpe:/a:ncpfs:ncpfs:2.2.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0013</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:45.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T14:35:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-665" xml:lang="en">DSA-665</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-44.xml" xml:lang="en">GLSA-200501-44</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6" xml:lang="en">ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12400" xml:lang="en">12400</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/433927/100/0/threaded" xml:lang="en">FLSA:152904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-371.html" xml:lang="en">RHSA-2005:371</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/13297" xml:lang="en">13297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:028" xml:lang="en">MDKSA-2005:028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013019" xml:lang="en">1013019</vuln:reference>
    </vuln:references>
    <vuln:summary>nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0014">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ncpfs:ncpfs:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ncpfs:ncpfs:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ncpfs:ncpfs:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ncpfs:ncpfs:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ncpfs:ncpfs:2.2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ncpfs:ncpfs:2.2.1</vuln:product>
      <vuln:product>cpe:/a:ncpfs:ncpfs:2.2.4</vuln:product>
      <vuln:product>cpe:/a:ncpfs:ncpfs:2.2.3</vuln:product>
      <vuln:product>cpe:/a:ncpfs:ncpfs:2.2.2</vuln:product>
      <vuln:product>cpe:/a:ncpfs:ncpfs:2.2.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0014</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:45.680-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T14:34:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-44.xml" xml:lang="en">GLSA-200501-44</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6" xml:lang="en">ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12400" xml:lang="en">12400</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/433927/100/0/threaded" xml:lang="en">FLSA:152904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/13298" xml:lang="en">13298</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:028" xml:lang="en">MDKSA-2005:028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013019" xml:lang="en">1013019</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in ncplogin in ncpfs before 2.2.6 allows remote malicious NetWare servers to execute arbitrary code on the NetWare client.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0015">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:crosswire_bible_society:sword:1.5.7a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:crosswire_bible_society:sword:1.5.7a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0015</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:45.743-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T14:42:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-650" xml:lang="en">DSA-650</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18997" xml:lang="en">sword-diatheke-command-execution(18997)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012955" xml:lang="en">1012955</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13897" xml:lang="en">13897</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12320" xml:lang="en">12320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13941" xml:lang="en">13941</vuln:reference>
    </vuln:references>
    <vuln:summary>diatheke.pl in Sword 1.5.7a allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0016">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gatos:gatos:0.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gatos:gatos:0.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0016</vuln:cve-id>
    <vuln:published-datetime>2005-04-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:05.950-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-640" xml:lang="en">DSA-640</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13884/" xml:lang="en">13884</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18930" xml:lang="en">gatos-xatitv-bo(18930)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the exported_display function in xatitv in gatos before 0.0.5 allows local users to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0017">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:f2c_open_source_project:f2c_translator:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2005-0017</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:06.107-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T14:41:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-661" xml:lang="en">DSA-661</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-43.xml" xml:lang="en">GLSA-200501-43</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12380" xml:lang="en">12380</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013028" xml:lang="en">1013028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14067" xml:lang="en">14067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14052" xml:lang="en">14052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14041" xml:lang="en">14041</vuln:reference>
    </vuln:references>
    <vuln:summary>The f2c translator in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0018">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:f2c_open_source_project:f2c_translator:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:f2c_open_source_project:f2c_translator:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0018</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:06.263-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T14:50:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12380" xml:lang="en">12380</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-661" xml:lang="en">DSA-661</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013028" xml:lang="en">1013028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14052" xml:lang="en">14052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14041" xml:lang="en">14041</vuln:reference>
    </vuln:references>
    <vuln:summary>The f2 shell script in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0019">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:yongguang_zhang:hztty:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:yongguang_zhang:hztty:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0019</vuln:cve-id>
    <vuln:published-datetime>2005-04-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:06.417-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12518" xml:lang="en">12518</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-675" xml:lang="en">DSA-675</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19297" xml:lang="en">hztty-command-execution(19297)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013154" xml:lang="en">1013154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14236" xml:lang="en">14236</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in hztty 2.0 and earlier allows local users to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0020">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.16"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.17"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.18"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.19"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.20"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.21"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.22"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.23"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.24"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.25"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.25.1"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.26"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:playmidi:playmidi:2.3.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.0"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.0::amd64"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.1"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.1::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:10.1</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:10.0::amd64</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.9</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.7</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.6</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.4</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:10.1::x86_64</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.16</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.19</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.20</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.3</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.14</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.13</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.22</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.24</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.26</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.2</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.12</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.23</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.18</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.11</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.10</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.25</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.25.1</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.17</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.15</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.1</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:10.0</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.8</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.5</vuln:product>
      <vuln:product>cpe:/a:playmidi:playmidi:2.3.21</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0020</vuln:cve-id>
    <vuln:published-datetime>2005-04-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:46.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-641" xml:lang="en">DSA-641</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18933" xml:lang="en">playmidi-bo(18933)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12274" xml:lang="en">12274</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/13049" xml:lang="en">13049</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:010" xml:lang="en">MDKSA-2005:010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012957" xml:lang="en">1012957</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13898" xml:lang="en">13898</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13890" xml:lang="en">13890</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13828" xml:lang="en">13828</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in playmidi before 2.4 allows local users to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0021">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:4.41"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:4.42"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:4.40"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:university_of_cambridge:exim:4.40</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:4.41</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:4.42</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0021</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:22.653-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T14:48:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10347" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10347" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/132992" xml:lang="en">VU#132992</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-025.html" xml:lang="en">RHSA-2005:025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=183&amp;type=vulnerabilities" xml:lang="en">20050114 Exim dns_buld_reverse() Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=179&amp;type=vulnerabilities" xml:lang="en">20050107 Exim host_aton() Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.exim.org/mail-archives/exim-users/Week-of-Mon-20050103/msg00028.html" xml:lang="en">[exim] 20050104 2 smallish security issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-637" xml:lang="en">DSA-637</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-635" xml:lang="en">DSA-635</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200501-23.xml" xml:lang="en">GLSA-200501-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44" xml:lang="en">http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10347" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10347" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which triggers an overflow in the dns_build_reverse function.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0022">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:4.41"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:4.42"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_cambridge:exim:4.40"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:university_of_cambridge:exim:4.40</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:4.41</vuln:product>
      <vuln:product>cpe:/a:university_of_cambridge:exim:4.42</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0022</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:22.797-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T14:57:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11293" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11293" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-025.html" xml:lang="en">RHSA-2005:025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.exim.org/mail-archives/exim-users/Week-of-Mon-20050103/msg00028.html" xml:lang="en">[exim] 20050104 2 smallish security issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=178&amp;type=vulnerabilities" xml:lang="en">20050107 Exim auth_spa_server() Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200501-23.xml" xml:lang="en">GLSA-200501-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110824870908614&amp;w=2" xml:lang="en">20050212 exim auth_spa_server() PoC exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44" xml:lang="en">http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12188" xml:lang="en">12188</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11293" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11293" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the auth_spa_client function, may allow attackers to execute arbitrary code during SPA authentication.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0023">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnome:libvte4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:libzvt2:1.4.2.19"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnome:libvte4</vuln:product>
      <vuln:product>cpe:/a:gnome:libzvt2:1.4.2.19</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0023</vuln:cve-id>
    <vuln:published-datetime>2005-10-05T17:02:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:27.267-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-10-06T14:34:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/22496" xml:lang="en">libzvt-gnomeptyhelper-spoof(22496)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2005/1931" xml:lang="en">ADV-2005-1931</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/15004" xml:lang="en">15004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/17023" xml:lang="en">17023</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112879572407250&amp;w=2" xml:lang="en">20051007 gnome-pty-helper writes arbitrary utmp records</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugzilla.gnome.org/show_bug.cgi?id=317312" xml:lang="en">http://bugzilla.gnome.org/show_bug.cgi?id=317312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330907" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330907</vuln:reference>
    </vuln:references>
    <vuln:summary>gnome-pty-helper in GNOME libzvt2 and libvte4 allows local users to spoof the logon hostname via a modified DISPLAY environment variable. NOTE: the severity of this issue has been disputed.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0033">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.4.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:isc:bind:8.4.4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.4.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0033</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:07.293-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T15:01:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/327633" xml:lang="en">VU#327633</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uniras.gov.uk/niscc/docs/al-20050125-00059.html" xml:lang="en">http://www.uniras.gov.uk/niscc/docs/al-20050125-00059.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.isc.org/index.pl?/sw/bind/bind8.php" xml:lang="en">http://www.isc.org/index.pl?/sw/bind/bind8.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.isc.org/index.pl?/sw/bind/bind-security.php" xml:lang="en">http://www.isc.org/index.pl?/sw/bind/bind-security.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19063" xml:lang="en">bind-qusedns-bo(19063)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12364" xml:lang="en">12364</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012996" xml:lang="en">1012996</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18291" xml:lang="en">18291</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14009" xml:lang="en">14009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.1/SCOSA-2006.1.txt" xml:lang="en">SCOSA-2006.1</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the code for recursion and glue fetching in BIND 8.4.4 and 8.4.5 allows remote attackers to cause a denial of service (crash) via queries that trigger the overflow in the q_usedns array that tracks nameservers and addresses.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0034">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:isc:bind:9.3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0034</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T15:13:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/938617" xml:lang="en">VU#938617</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19062" xml:lang="en">bind-named-dns-dos(19062)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uniras.gov.uk/niscc/docs/al-20050125-00060.html" xml:lang="en">http://www.uniras.gov.uk/niscc/docs/al-20050125-00060.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.isc.org/index.pl?/sw/bind/bind-security.php" xml:lang="en">http://www.isc.org/index.pl?/sw/bind/bind-security.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2005/0003/" xml:lang="en">2005-0003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12365" xml:lang="en">12365</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.isc.org/index.pl?/sw/bind/bind9.php" xml:lang="en">http://www.isc.org/index.pl?/sw/bind/bind9.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012995" xml:lang="en">1012995</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14008" xml:lang="en">14008</vuln:reference>
    </vuln:references>
    <vuln:summary>An "incorrect assumption" in the authvalidated validator function in BIND 9.3.0, when DNSSEC is enabled, allows remote attackers to cause a denial of service (named server exit) via crafted DNS packets that cause an internal consistency test (self-check) to fail.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0035">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat_reader:4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:5.0.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:5.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0035</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:27.673-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T15:31:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2005/0310" xml:lang="en">ADV-2005-0310</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.niscc.gov.uk/niscc/docs/re-20050401-00264.pdf" xml:lang="en">http://www.niscc.gov.uk/niscc/docs/re-20050401-00264.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hyperdose.com/advisories/H2005-06.txt" xml:lang="en">http://www.hyperdose.com/advisories/H2005-06.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/techdocs/331465.html" xml:lang="en">http://www.adobe.com/support/techdocs/331465.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12989" xml:lang="en">12989</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/15242" xml:lang="en">15242</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14813" xml:lang="en">14813</vuln:reference>
    </vuln:references>
    <vuln:summary>The Acrobat web control in Adobe Acrobat and Acrobat Reader 7.0 and earlier, when used with Internet Explorer, allows remote attackers to determine the existence of arbitrary files via the LoadFile ActiveX method.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0036">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:5.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:7.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:7.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:7.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:7.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:7.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:7.9.11"/>
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:8.10"/>
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:8.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:8.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:8.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:8.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:8.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:8.9"/>
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:8.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:8.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:8.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:8.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:8.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:8.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:etl:delegate:5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:etl:delegate:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:delegate:delegate:8.10.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:delegate:delegate:8.9.5</vuln:product>
      <vuln:product>cpe:/a:delegate:delegate:7.8.2</vuln:product>
      <vuln:product>cpe:/a:delegate:delegate:8.3.4</vuln:product>
      <vuln:product>cpe:/a:delegate:delegate:8.9.6</vuln:product>
      <vuln:product>cpe:/a:etl:delegate:5.9</vuln:product>
      <vuln:product>cpe:/a:delegate:delegate:8.3.3</vuln:product>
      <vuln:product>cpe:/a:delegate:delegate:7.7.1</vuln:product>
      <vuln:product>cpe:/a:delegate:delegate:8.9.4</vuln:product>
      <vuln:product>cpe:/a:delegate:delegate:7.8.1</vuln:product>
      <vuln:product>cpe:/a:delegate:delegate:8.10.1</vuln:product>
      <vuln:product>cpe:/a:delegate:delegate:8.9.1</vuln:product>
      <vuln:product>cpe:/a:delegate:delegate:8.5.0</vuln:product>
      <vuln:product>cpe:/a:delegate:delegate:7.7.0</vuln:product>
      <vuln:product>cpe:/a:delegate:delegate:5.9.3</vuln:product>
      <vuln:product>cpe:/a:delegate:delegate:8.4.0</vuln:product>
      <vuln:product>cpe:/a:etl:delegate:6.0</vuln:product>
      <vuln:product>cpe:/a:delegate:delegate:7.9.11</vuln:product>
      <vuln:product>cpe:/a:delegate:delegate:8.10</vuln:product>
      <vuln:product>cpe:/a:delegate:delegate:8.9.3</vuln:product>
      <vuln:product>cpe:/a:delegate:delegate:8.9</vuln:product>
      <vuln:product>cpe:/a:delegate:delegate:8.10.2</vuln:product>
      <vuln:product>cpe:/a:delegate:delegate:8.9.2</vuln:product>
      <vuln:product>cpe:/a:delegate:delegate:7.8.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0036</vuln:cve-id>
    <vuln:published-datetime>2005-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:07.777-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-04-28T13:39:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en" xml:lang="en">http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html" xml:lang="en">http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/13729" xml:lang="en">13729</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/25291" xml:lang="en">25291</vuln:reference>
    </vuln:references>
    <vuln:summary>The DNS implementation in DeleGate 8.10.2 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0037">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:dnrd:dnrd:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:dnrd:dnrd:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:dnrd:dnrd:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:dnrd:dnrd:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:dnrd:dnrd:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:dnrd:dnrd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:dnrd:dnrd:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:dnrd:dnrd:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:dnrd:dnrd:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:dnrd:dnrd:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:dnrd:dnrd:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:dnrd:dnrd:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:dnrd:dnrd:2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:dnrd:dnrd:2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:dnrd:dnrd:2.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dnrd:dnrd:1.4</vuln:product>
      <vuln:product>cpe:/a:dnrd:dnrd:2.4</vuln:product>
      <vuln:product>cpe:/a:dnrd:dnrd:1.1</vuln:product>
      <vuln:product>cpe:/a:dnrd:dnrd:2.1</vuln:product>
      <vuln:product>cpe:/a:dnrd:dnrd:2.8</vuln:product>
      <vuln:product>cpe:/a:dnrd:dnrd:2.3</vuln:product>
      <vuln:product>cpe:/a:dnrd:dnrd:1.2</vuln:product>
      <vuln:product>cpe:/a:dnrd:dnrd:2.7</vuln:product>
      <vuln:product>cpe:/a:dnrd:dnrd:2.0</vuln:product>
      <vuln:product>cpe:/a:dnrd:dnrd:2.5</vuln:product>
      <vuln:product>cpe:/a:dnrd:dnrd:1.0</vuln:product>
      <vuln:product>cpe:/a:dnrd:dnrd:1.3</vuln:product>
      <vuln:product>cpe:/a:dnrd:dnrd:2.9</vuln:product>
      <vuln:product>cpe:/a:dnrd:dnrd:2.6</vuln:product>
      <vuln:product>cpe:/a:dnrd:dnrd:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0037</vuln:cve-id>
    <vuln:published-datetime>2005-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:08.060-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-04-28T13:43:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html" xml:lang="en">http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/13729" xml:lang="en">13729</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/25291" xml:lang="en">25291</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en" xml:lang="en">http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en</vuln:reference>
    </vuln:references>
    <vuln:summary>The DNS implementation of DNRD before 2.10 allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0038">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:powerdns:powerdns:2.0_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:powerdns:powerdns:2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:powerdns:powerdns:2.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:powerdns:powerdns:2.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:powerdns:powerdns:2.9.10"/>
        <cpe-lang:fact-ref name="cpe:/a:powerdns:powerdns:2.9.11"/>
        <cpe-lang:fact-ref name="cpe:/a:powerdns:powerdns:2.9.12"/>
        <cpe-lang:fact-ref name="cpe:/a:powerdns:powerdns:2.9.13"/>
        <cpe-lang:fact-ref name="cpe:/a:powerdns:powerdns:2.9.14"/>
        <cpe-lang:fact-ref name="cpe:/a:powerdns:powerdns:2.9.15"/>
        <cpe-lang:fact-ref name="cpe:/a:powerdns:powerdns:2.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:powerdns:powerdns:2.9.3a"/>
        <cpe-lang:fact-ref name="cpe:/a:powerdns:powerdns:2.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:powerdns:powerdns:2.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:powerdns:powerdns:2.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:powerdns:powerdns:2.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:powerdns:powerdns:2.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:powerdns:powerdns:2.9.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:powerdns:powerdns:2.9.7</vuln:product>
      <vuln:product>cpe:/a:powerdns:powerdns:2.9.0</vuln:product>
      <vuln:product>cpe:/a:powerdns:powerdns:2.9.16</vuln:product>
      <vuln:product>cpe:/a:powerdns:powerdns:2.9.8</vuln:product>
      <vuln:product>cpe:/a:powerdns:powerdns:2.9.12</vuln:product>
      <vuln:product>cpe:/a:powerdns:powerdns:2.9.13</vuln:product>
      <vuln:product>cpe:/a:powerdns:powerdns:2.9.3a</vuln:product>
      <vuln:product>cpe:/a:powerdns:powerdns:2.9.10</vuln:product>
      <vuln:product>cpe:/a:powerdns:powerdns:2.9.14</vuln:product>
      <vuln:product>cpe:/a:powerdns:powerdns:2.0_rc1</vuln:product>
      <vuln:product>cpe:/a:powerdns:powerdns:2.8</vuln:product>
      <vuln:product>cpe:/a:powerdns:powerdns:2.9.11</vuln:product>
      <vuln:product>cpe:/a:powerdns:powerdns:2.9.5</vuln:product>
      <vuln:product>cpe:/a:powerdns:powerdns:2.9.2</vuln:product>
      <vuln:product>cpe:/a:powerdns:powerdns:2.9.1</vuln:product>
      <vuln:product>cpe:/a:powerdns:powerdns:2.9.15</vuln:product>
      <vuln:product>cpe:/a:powerdns:powerdns:2.9.4</vuln:product>
      <vuln:product>cpe:/a:powerdns:powerdns:2.9.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0038</vuln:cve-id>
    <vuln:published-datetime>2005-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:08.247-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-04-28T13:46:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html" xml:lang="en">http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/13729" xml:lang="en">13729</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/25291" xml:lang="en">25291</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en" xml:lang="en">http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en</vuln:reference>
    </vuln:references>
    <vuln:summary>The DNS implementation of PowerDNS 2.9.16 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0039">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:nissc:ipsec:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nissc:ipsec:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0039</vuln:cve-id>
    <vuln:published-datetime>2005-05-10T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:27.923-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-12T14:12:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/302220" xml:lang="en">VU#302220</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2005/2806" xml:lang="en">ADV-2005-2806</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2005/0507" xml:lang="en">ADV-2005-0507</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/407774" xml:lang="en">SSRT5957</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.niscc.gov.uk/niscc/docs/al-20050509-00386.html?lang=en" xml:lang="en">http://www.niscc.gov.uk/niscc/docs/al-20050509-00386.html?lang=en</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/13562" xml:lang="en">13562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/407774" xml:lang="en">HPSBTU01217</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015320" xml:lang="en">1015320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/17938" xml:lang="en">17938</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111566201610350&amp;w=2" xml:lang="en">20050509 NISCC Vulnerability Advisory IPSEC - 004033</vuln:reference>
    </vuln:references>
    <vuln:summary>Certain configurations of IPsec, when using Encapsulating Security Payload (ESP) in tunnel mode, integrity protection at a higher layer, or Authentication Header (AH), allow remote attackers to decrypt IPSec communications by modifying the outer packet in ways that cause plaintext data from the inner packet to be returned in ICMP messages, as demonstrated using bit-flipping attacks and (1) Destination Address Rewriting, (2) a modified header length that causes portions of the packet to be interpreted as IP Options, or (3) a modified protocol field and source address.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0040">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:dotnetnuke:dotnetnuke:3.0.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dotnetnuke:dotnetnuke:3.0.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0040</vuln:cve-id>
    <vuln:published-datetime>2005-05-19T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:08.590-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-26T11:49:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.woany.co.uk/advisories/dotnetnukexss.txt" xml:lang="en">http://www.woany.co.uk/advisories/dotnetnukexss.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/15397" xml:lang="en">15397</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111627180518591&amp;w=2" xml:lang="en">20050516 DotNetNuke (Multiple XSS)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/13647" xml:lang="en">13647</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/13646" xml:lang="en">13646</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/13644" xml:lang="en">13644</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke before 3.0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) register a new user page, (2) User-Agent, or (3) Username, which is not properly quoted before sending to the error log.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0043">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0043</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:08.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T15:19:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/377368" xml:lang="en">VU#377368</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=180&amp;type=vulnerabilities" xml:lang="en">20050113 Apple iTunes Playlist Parsing Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2005/Jan/msg00000.html" xml:lang="en">APPLE-SA-2005-01-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18851" xml:lang="en">itunes-m3u-pls-bo(18851)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12238" xml:lang="en">12238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/12833" xml:lang="en">12833</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012839" xml:lang="en">1012839</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13804" xml:lang="en">13804</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2) .pls playlist files.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0044">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:advanced_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0044</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:49.367-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T15:26:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4499" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4499" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3568" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3568" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2917" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2917" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1180" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1180" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/927889" xml:lang="en">VU#927889</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" xml:lang="en">TA05-039A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms05-012.mspx" xml:lang="en">MS05-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19109" xml:lang="en">win-ole-code-execution(19109)</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2917" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2917" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3568" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3568" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1180" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1180" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4499" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4499" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2005-0045">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:advanced_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0045</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:49.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T15:32:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4043" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4043" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1889" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1889" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1847" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1847" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1606" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1606" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" xml:lang="en">TA05-039A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/652537" xml:lang="en">VU#652537</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19089" xml:lang="en">win-smb-code-execution(19089)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms05-011.mspx" xml:lang="en">MS05-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=110795643831169&amp;w=2" xml:lang="en">20050209 EEYE: Windows SMB Client Transaction Response Handling Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111040962600205&amp;w=2" xml:lang="en">20050309 Update: MS05-011 EEYE: Windows SMB Client Transaction Response Handling Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110792638401852&amp;w=2" xml:lang="en">20050209 EEYE: Windows SMB Client Transaction Response Handling Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12484" xml:lang="en">12484</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1847" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1847" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1606" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1606" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1889" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1889" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4043" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4043" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 commands, aka the "Server Message Block Vulnerability," and as demonstrated using Trans2 FIND_FIRST2 responses with large file name length fields.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0047">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:advanced_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0047</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:49.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T15:36:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:901" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:901" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2892" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2892" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2351" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2351" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1159" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1159" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" xml:lang="en">TA05-039A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/597889" xml:lang="en">VU#597889</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms05-012.mspx" xml:lang="en">MS05-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19105" xml:lang="en">win-com-gain-privileges(19105)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.argeniss.com/research/SSExploit.c" xml:lang="en">http://www.argeniss.com/research/SSExploit.c</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111755870828817&amp;w=2" xml:lang="en">20050530 [Argeniss] MS05-012 Exploit</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1159" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1159" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:901" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:901" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2892" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2892" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2351" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2351" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2005-0048">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::embedded"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:embedded"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:embedded</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::embedded</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:advanced_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0048</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:50.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T15:40:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4549" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4549" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3824" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3824" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1744" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1744" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA05-102A.html" xml:lang="en">TA05-102A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/233754" xml:lang="en">VU#233754</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx" xml:lang="en">MS05-019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/alerts/id/192" xml:lang="en">20050412 Windows IP Options Remote Compromise</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1744" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1744" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3824" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3824" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4549" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4549" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2005-0049">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_portal_server:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_portal_server:2003:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_team_services"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:sharepoint_portal_server:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:sharepoint_team_services</vuln:product>
      <vuln:product>cpe:/a:microsoft:sharepoint_portal_server:2003:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0049</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:09.933-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T15:46:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" xml:lang="en">TA05-039A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/340409" xml:lang="en">VU#340409</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms05-006.mspx" xml:lang="en">MS05-006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19091" xml:lang="en">win-sharepoint-services-xss(19091)</vuln:reference>
    </vuln:references>
    <vuln:summary>Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to spoof the web cache.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0050">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:2000::small_business_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:2003::small_business_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:2003::small_business_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:2000::small_business_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:advanced_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0050</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-04-03T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T15:50:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:644" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:644" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4786" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4786" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3582" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3582" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2568" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2568" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" xml:lang="en">TA05-039A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/130433" xml:lang="en">VU#130433</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms05-010.mspx" xml:lang="en">MS05-010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19101" xml:lang="en">win-license-code-execution(19101)</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3582" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3582" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:644" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:644" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2568" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2568" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4786" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4786" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, aka the "License Logging Service Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2005-0051">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:tablet_pc"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:tablet_pc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0051</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:50.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T15:51:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3055" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3055" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2292" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2292" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" xml:lang="en">TA05-039A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/939074" xml:lang="en">VU#939074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms05-007.mspx" xml:lang="en">MS05-007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19093" xml:lang="en">win-named-pipe-information-disclosure(19093)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12486" xml:lang="en">12486</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013112" xml:lang="en">1013112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14189" xml:lang="en">14189</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3055" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3055" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2292" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2292" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing resources) via an anonymous logon using a named pipe, which is not properly authenticated, aka the "Named Pipe Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2005-0053">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:advanced_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0053</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:50.633-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T15:58:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4864" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4864" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4726" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4726" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3006" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3006" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2953" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2953" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2046" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2046" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1334" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1334" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1015" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1015" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" xml:lang="en">TA05-039A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/698835" xml:lang="en">VU#698835</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19117" xml:lang="en">ie-dragdrop-gain-privileges(19117)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11466" xml:lang="en">11466</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx" xml:lang="en">MS05-014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms05-008.mspx" xml:lang="en">MS05-008</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3006" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3006" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2046" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2046" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4864" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4864" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2953" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2953" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1015" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1015" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1334" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1334" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4726" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4726" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2005-0054">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.01"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6:windows_server_2003_sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6:windows_server_2003_sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0054</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:50.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T16:00:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3586" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3586" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3196" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3196" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3060" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3060" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1736" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1736" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1308" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1308" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" xml:lang="en">TA05-039A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/580299" xml:lang="en">VU#580299</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx" xml:lang="en">MS05-014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110796851002781&amp;w=2" xml:lang="en">20050209 Internet Explorer zone spoofing with encoded URLs</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19214" xml:lang="en">ie-file-url-encode(19214)</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1736" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1736" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3586" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3586" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3060" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3060" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3196" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3196" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1308" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1308" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2005-0055">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0055</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-12-06T00:34:18.830-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T16:09:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:710" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:710" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3910" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3910" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3137" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3137" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2692" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2692" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1005" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1005" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" xml:lang="en">TA05-039A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/843771" xml:lang="en">VU#843771</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx" xml:lang="en">MS05-014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19137" xml:lang="en">ie-cdf-execute-code(19137)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013125" xml:lang="en">1013125</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3910" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3910" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2692" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2692" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1005" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1005" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:710" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:710" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3137" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3137" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2005-0056">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.01"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6:windows_server_2003_sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6:windows_server_2003_sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0056</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:50.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T16:02:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4947" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4947" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4085" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4085" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3318" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3318" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2817" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2817" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2385" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2385" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" xml:lang="en">TA05-039A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/823971" xml:lang="en">VU#823971</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12427" xml:lang="en">12427</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx" xml:lang="en">MS05-014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19137" xml:lang="en">ie-cdf-execute-code(19137)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013126" xml:lang="en">1013126</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2385" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2385" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2817" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2817" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4085" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4085" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3318" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3318" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4947" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4947" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2005-0057">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:advanced_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0057</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:50.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T16:13:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:713" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:713" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3203" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3203" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2570" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2570" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" xml:lang="en">TA05-039A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/820427" xml:lang="en">VU#820427</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms05-015.mspx" xml:lang="en">MS05-015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19110" xml:lang="en">win-hyperlink-code-execution(19110)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12479" xml:lang="en">12479</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013119" xml:lang="en">1013119</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14195" xml:lang="en">14195</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3203" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3203" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2570" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2570" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:713" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:713" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a crafted link that triggers an "unchecked buffer" in the library, possibly due to a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0058">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0058</vuln:cve-id>
    <vuln:published-datetime>2005-08-10T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:50.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-08-10T07:34:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1297" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1297" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1213" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1213" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1075" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1075" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:100088" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100088" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:100086" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100086" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:100085" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100085" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:100084" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100084" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/Security/bulletin/ms05-040.mspx" xml:lang="en">MS05-040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/16354/" xml:lang="en">16354</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/14518" xml:lang="en">14518</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1014639" xml:lang="en">1014639</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1213" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1213" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1297" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1297" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:100086" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:100086" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1075" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1075" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:100085" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:100085" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:100084" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:100084" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:100088" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:100088" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0059">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::embedded"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:embedded"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:embedded</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::embedded</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:advanced_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0059</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:51.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T16:18:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4988" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4988" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4384" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4384" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms05-017.mspx" xml:lang="en">MS05-017</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4988" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4988" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4384" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4384" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0060">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:advanced_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0060</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:51.133-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T16:23:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4797" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4797" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3941" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3941" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2731" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2731" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2562" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2562" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms05-018.mspx" xml:lang="en">MS05-018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ngssoftware.com/advisories/ms-01.txt" xml:lang="en">http://www.ngssoftware.com/advisories/ms-01.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111343529426926&amp;w=2" xml:lang="en">20050413 Windows kernel overflow fixed</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4797" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4797" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2562" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2562" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2731" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2731" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3941" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3941" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0061">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:media_center"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:advanced_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0061</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:51.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T16:29:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4593" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4593" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3994" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3994" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1761" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1761" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1656" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1656" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms05-018.mspx" xml:lang="en">MS05-018</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1761" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1761" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1656" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1656" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4593" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4593" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3994" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3994" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0063">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:advanced_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0063</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:29.330-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-13T16:34:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:587" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:587" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:573" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:573" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4710" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4710" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:407" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:407" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3456" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3456" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2184" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2184" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms05-016.mspx" xml:lang="en">MS05-016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=231&amp;type=vulnerabilities" xml:lang="en">20050412 Microsoft MSHTA Script Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2005/0335" xml:lang="en">ADV-2005-0335</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/exploits/5YP0T0AFFW.html" xml:lang="en">http://www.securiteam.com/exploits/5YP0T0AFFW.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/13132" xml:lang="en">13132</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111755356016155&amp;w=2" xml:lang="en">20050529 Spam exploiting MS05-016</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3456" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3456" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4710" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4710" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:407" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:407" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:573" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:573" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2184" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2184" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:587" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:587" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0064">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.5a"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.7a"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.80"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.90"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.91"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.91a"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.91b"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.91c"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.92"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.92a"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.92b"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.92c"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.92d"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.92e"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.93"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.93a"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.93b"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.93c"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:1.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xpdf:xpdf:0.93</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.92b</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:1.1</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.7</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:1.0</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.90</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.4</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.92a</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.7a</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:3.0</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.91a</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:2.2</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.93b</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.5a</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.91c</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.92d</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:2.0</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.3</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:2.1</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.2</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:1.0a</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.92e</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.93c</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:2.3</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.80</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.6</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.93a</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.91b</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.92</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.92c</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.5</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.91</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0064</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:25.717-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T14:48:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11781" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11781" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://bugzilla.fedora.us/show_bug.cgi?id=2353" xml:lang="en">FLSA:2353</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://bugzilla.fedora.us/show_bug.cgi?id=2352" xml:lang="en">FLSA:2352</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2005/0003/" xml:lang="en">2005-0003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-066.html" xml:lang="en">RHSA-2005:066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-059.html" xml:lang="en">RHSA-2005:059</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-057.html" xml:lang="en">RHSA-2005:057</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-053.html" xml:lang="en">RHSA-2005:053</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-034.html" xml:lang="en">RHSA-2005:034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=186&amp;type=vulnerabilities" xml:lang="en">20050118 Multiple Unix/Linux Vendor Xpdf makeFileKey2 Stack Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-28.xml" xml:lang="en">GLSA-200502-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-648" xml:lang="en">DSA-648</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-645" xml:lang="en">DSA-645</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110625368019554&amp;w=2" xml:lang="en">20050119 [USN-64-1] xpdf, CUPS vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000921" xml:lang="en">CLA-2005:921</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.00pl3.patch" xml:lang="en">ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.00pl3.patch</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-026.html" xml:lang="en">RHSA-2005:026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/17277" xml:lang="en">17277</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.42/SCOSA-2005.42.txt" xml:lang="en">SCOSA-2005.42</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:021" xml:lang="en">MDKSA-2005:021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:020" xml:lang="en">MDKSA-2005:020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:019" xml:lang="en">MDKSA-2005:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:018" xml:lang="en">MDKSA-2005:018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:017" xml:lang="en">MDKSA-2005:017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:016" xml:lang="en">MDKSA-2005:016</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11781" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11781" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0065">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:tcp:tcp"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tcp:tcp</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0065</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:12.967-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T14:23:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html" xml:lang="en">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/13124" xml:lang="en">13124</vuln:reference>
    </vuln:references>
    <vuln:summary>The original design of TCP does not check that the TCP sequence number in an ICMP error message is within the range of sequence numbers for data that has been sent but not acknowledged (aka "TCP sequence number checking"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0066">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:tcp:tcp"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tcp:tcp</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0066</vuln:cve-id>
    <vuln:published-datetime>2004-12-22T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:13.120-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T14:35:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html" xml:lang="en">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/13124" xml:lang="en">13124</vuln:reference>
    </vuln:references>
    <vuln:summary>The original design of TCP does not check that the TCP Acknowledgement number in an ICMP error message generated by an intermediate router is within the range of possible values for data that has already been acknowledged (aka "TCP acknowledgement number checking"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0067">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:tcp:tcp"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tcp:tcp</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0067</vuln:cve-id>
    <vuln:published-datetime>2004-12-22T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:13.277-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T14:40:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html" xml:lang="en">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/13124" xml:lang="en">13124</vuln:reference>
    </vuln:references>
    <vuln:summary>The original design of TCP does not require that port numbers be assigned randomly (aka "Port randomization"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0068">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:tcp:tcp"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tcp:tcp</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0068</vuln:cve-id>
    <vuln:published-datetime>2004-12-22T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:13.417-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T14:44:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html" xml:lang="en">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/13124" xml:lang="en">13124</vuln:reference>
    </vuln:references>
    <vuln:summary>The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0069">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:vim_development_group:vim:6.3.011"/>
        <cpe-lang:fact-ref name="cpe:/a:vim_development_group:vim:6.3.025"/>
        <cpe-lang:fact-ref name="cpe:/a:vim_development_group:vim:6.3.030"/>
        <cpe-lang:fact-ref name="cpe:/a:vim_development_group:vim:6.3.044"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vim_development_group:vim:6.3.030</vuln:product>
      <vuln:product>cpe:/a:vim_development_group:vim:6.3.025</vuln:product>
      <vuln:product>cpe:/a:vim_development_group:vim:6.3.011</vuln:product>
      <vuln:product>cpe:/a:vim_development_group:vim:6.3.044</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0069</vuln:cve-id>
    <vuln:published-datetime>2005-01-13T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:26.187-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T15:01:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9402" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9402" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18870" xml:lang="en">vim-symlink(18870)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-122.html" xml:lang="en">RHSA-2005:122</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-036.html" xml:lang="en">RHSA-2005:036</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13841/" xml:lang="en">13841</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608387001863&amp;w=2" xml:lang="en">20050118 [USN-61-1] vim vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://bugzilla.fedora.us/show_bug.cgi?id=2343" xml:lang="en">FLSA:2343</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012938" xml:lang="en">1012938</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9402" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9402" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0070">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:synaesthesia:synaesthesia:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:synaesthesia:synaesthesia:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0070</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:13.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T14:56:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-681" xml:lang="en">DSA-681</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12546" xml:lang="en">12546</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013206" xml:lang="en">1013206</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14300" xml:lang="en">14300</vuln:reference>
    </vuln:references>
    <vuln:summary>Synaesthesia 2.1 and earlier, and possibly other versions, when installed setuid root, does not drop privileges before processing configuration and mixer files, which allows local users to read arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0071">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:vdr:vdr:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vdr:vdr:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:vdr:vdr:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vdr:vdr:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vdr:vdr:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:vdr:vdr:1.2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vdr:vdr:1.0.0</vuln:product>
      <vuln:product>cpe:/a:vdr:vdr:1.0.4</vuln:product>
      <vuln:product>cpe:/a:vdr:vdr:1.2.5</vuln:product>
      <vuln:product>cpe:/a:vdr:vdr:1.2.1</vuln:product>
      <vuln:product>cpe:/a:vdr:vdr:1.2.2</vuln:product>
      <vuln:product>cpe:/a:vdr:vdr:1.2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0071</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:13.903-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T15:03:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19066" xml:lang="en">vdr-dvdapi-file-overwrite(19066)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-42.xml" xml:lang="en">GLSA-200501-42</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-656" xml:lang="en">DSA-656</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12356" xml:lang="en">12356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14066" xml:lang="en">14066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13995" xml:lang="en">13995</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13930" xml:lang="en">13930</vuln:reference>
    </vuln:references>
    <vuln:summary>vdr before 1.2.6 does not securely create files, which allows attackers to overwrite arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0072">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ejoy_and_hu_yong:zhcon:0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ejoy_and_hu_yong:zhcon:0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0072</vuln:cve-id>
    <vuln:published-datetime>2005-01-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:51.897-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T15:22:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-655" xml:lang="en">DSA-655</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19045" xml:lang="en">zhcon-information-disclosure(19045)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12343" xml:lang="en">12343</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:012" xml:lang="en">MDKSA-2005:012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012977" xml:lang="en">1012977</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13987" xml:lang="en">13987</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13982" xml:lang="en">13982</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13977" xml:lang="en">13977</vuln:reference>
    </vuln:references>
    <vuln:summary>zhcon before 0.2 does not drop privileges before reading a user configuration file, which allows local users to read arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0073">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:debian:sympa:3.3.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:debian:sympa:3.3.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0073</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:14.247-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T15:06:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-677" xml:lang="en">DSA-677</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013163" xml:lang="en">1013163</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14224" xml:lang="en">14224</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14217" xml:lang="en">14217</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in queue.c in a support script for sympa 3.3.3, when running setuid, allows local users to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0074">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xpcd:xpcd:2.08"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xpcd:xpcd:2.08</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0074</vuln:cve-id>
    <vuln:published-datetime>2005-02-11T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:14.403-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T16:50:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-676" xml:lang="en">DSA-676</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12523" xml:lang="en">12523</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013162" xml:lang="en">1013162</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14250" xml:lang="en">14250</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14248" xml:lang="en">14248</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in pcdsvgaview in xpcd 2.08 allows local users to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0075">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3a</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.0.5</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.6</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.0.4</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.2</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.4</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.5</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.8</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.0</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.0</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.11</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.7</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.2</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.9</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.10</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0075</vuln:cve-id>
    <vuln:published-datetime>2005-01-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:26.717-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-06T10:16:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9587" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9587" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squirrelmail.org/security/issue/2005-01-14" xml:lang="en">http://www.squirrelmail.org/security/issue/2005-01-14</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-135.html" xml:lang="en">RHSA-2005:135</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-099.html" xml:lang="en">RHSA-2005:099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13962/" xml:lang="en">13962</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" xml:lang="en">APPLE-SA-2005-03-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2" xml:lang="en">20050129 SquirrelMail Security Advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml" xml:lang="en">GLSA-200501-39</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9587" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9587" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>prefs.php in SquirrelMail before 1.4.4, with register_globals enabled, allows remote attackers to inject local code into the SquirrelMail code via custom preference handlers.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0076">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:debian:debian_linux:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0076</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:14.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T21:25:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19271" xml:lang="en">xview-xvparseone-bo(19271)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-672" xml:lang="en">DSA-672</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in the XView library 3.2 may allow local users to execute arbitrary code via setuid applications that use the library.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0077">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::woody"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:4.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:4.0</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::advanced_server</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::woody</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:4.10</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::workstation</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0077</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:26.937-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T22:05:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10552" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10552" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19068" xml:lang="en">dbi-library-file-overwrite(19068)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-072.html" xml:lang="en">RHSA-2005:072</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-38.xml" xml:lang="en">GLSA-200501-38</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-658" xml:lang="en">DSA-658</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110667936707597&amp;w=2" xml:lang="en">20050125 [USN-70-1] Perl DBI module vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12360" xml:lang="en">12360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/426530/30/6600/threaded" xml:lang="en">FLSA-2006:178989</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:030" xml:lang="en">MDKSA-2005:030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013007" xml:lang="en">1013007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14050" xml:lang="en">14050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14015" xml:lang="en">14015</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10552" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10552" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0078">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::woody"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.1_beta1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.1_beta2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:2.2_beta1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0_beta_1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.0_beta_2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::advanced_servers"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux_advanced_workstation:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:kde:kde:1.1.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.2</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::advanced_servers</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.3</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.0</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.2_beta1</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:1.1</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::workstation</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.4</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::woody</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.2</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0_beta_1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.2.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.1_beta1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.1_beta2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:1.0</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:3.0</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.0_beta_2</vuln:product>
      <vuln:product>cpe:/o:redhat:linux_advanced_workstation:2.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:1.1.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:2.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0078</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:27.060-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T22:22:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9260" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9260" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19084" xml:lang="en">kdebase-screensaver-security-bypass(19084)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-009.html" xml:lang="en">RHSA-2005:009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-660" xml:lang="en">DSA-660</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9260" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9260" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain function call, which allows attackers with physical access to cause a crash and access the desktop session.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0079">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xtrlock:xtrlock:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xtrlock:xtrlock:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0079</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:52.540-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T22:16:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-649" xml:lang="en">DSA-649</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18991" xml:lang="en">xtrlock-screen-lock-bypass(18991)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12316" xml:lang="en">12316</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13938" xml:lang="en">13938</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in xtrlock 2.0 allows local users to cause a denial of service (application crash) and hijack the desktop session.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0080">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:4.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:mailman:2.1.5</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:4.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0080</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:15.467-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T22:22:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549296126351&amp;w=2" xml:lang="en">20050110 [USN-59-1] mailman vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://qa.debian.org/bts-security.html" xml:lang="en">http://qa.debian.org/bts-security.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=285839" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=285839</vuln:reference>
    </vuln:references>
    <vuln:summary>The 55_options_traceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10 displays a different error message depending on whether the e-mail address is subscribed to a private list, which allows remote attackers to determine the list membership for a given e-mail address.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0081">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00.08"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00.19"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mysql:maxdb:7.5.00.12</vuln:product>
      <vuln:product>cpe:/a:mysql:maxdb:7.5.00.08</vuln:product>
      <vuln:product>cpe:/a:mysql:maxdb:7.5.00.18</vuln:product>
      <vuln:product>cpe:/a:mysql:maxdb:7.5.00.19</vuln:product>
      <vuln:product>cpe:/a:mysql:maxdb:7.5.00.15</vuln:product>
      <vuln:product>cpe:/a:mysql:maxdb:7.5.00</vuln:product>
      <vuln:product>cpe:/a:mysql:maxdb:7.5.00.14</vuln:product>
      <vuln:product>cpe:/a:mysql:maxdb:7.5.00.16</vuln:product>
      <vuln:product>cpe:/a:mysql:maxdb:7.5.00.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0081</vuln:cve-id>
    <vuln:published-datetime>2005-04-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:30.657-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=187&amp;type=vulnerabilities" xml:lang="en">20050119 MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via an HTTP request with invalid headers.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0082">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00.08"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00.19"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mysql:maxdb:7.5.00.12</vuln:product>
      <vuln:product>cpe:/a:mysql:maxdb:7.5.00.08</vuln:product>
      <vuln:product>cpe:/a:mysql:maxdb:7.5.00.18</vuln:product>
      <vuln:product>cpe:/a:mysql:maxdb:7.5.00.19</vuln:product>
      <vuln:product>cpe:/a:mysql:maxdb:7.5.00.15</vuln:product>
      <vuln:product>cpe:/a:mysql:maxdb:7.5.00</vuln:product>
      <vuln:product>cpe:/a:mysql:maxdb:7.5.00.14</vuln:product>
      <vuln:product>cpe:/a:mysql:maxdb:7.5.00.16</vuln:product>
      <vuln:product>cpe:/a:mysql:maxdb:7.5.00.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0082</vuln:cve-id>
    <vuln:published-datetime>2005-04-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:30.750-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=187&amp;type=vulnerabilities" xml:lang="en">20050119 MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>The sapdbwa_GetUserData function in MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via invalid parameters to the WebDAV handler code, which triggers a null dereference that causes the SAP DB Web Agent to crash.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0083">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mysql:maxdb:7.5.00</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0083</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:30.847-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T22:25:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19687" xml:lang="en">maxdb-null-pointer-dos(19687)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=218&amp;type=vulnerabilities" xml:lang="en">20050314 MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>MySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers to cause a denial of service (application crash) via invalid parameters to the (1) DBMCli_String::ReallocString, (2) DBMCli_String::operator, (3) DBMCli_Buffer::ForceResize, (4) DBMCli_Wizard::InstallDatabase, (5) DBMCli_Devspaces::Complete, (6) DBMWeb_TemplateWizard::askForWriteCountStep5, or (7) DBMWeb_DBMWeb::wizardDB functions, which triggers a null dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0084">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.10.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.8.13"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.8.14"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.8.15"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.8.16"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.8.17a"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.8.18"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.8.19"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.8.20"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.11"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.12"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.13"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.14"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.15"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.16"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ethereal_group:ethereal:0.9.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.8</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.8</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.11</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.16</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.2</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.4</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.5</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.8.14</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.1</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.12</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.7</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.2</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.8</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.15</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.0</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.3</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.0</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.4</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.8.15</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.5</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.3</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.7</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.9</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.14</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.8.20</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.10</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.6</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.8.17a</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.13</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.8.16</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.8.18</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.8.13</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.1</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.8.19</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.9.6</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10.0a</vuln:product>
      <vuln:product>cpe:/a:ethereal_group:ethereal:0.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0084</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:27.733-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T22:30:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9140" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9140" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml" xml:lang="en">GLSA-200501-27</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-653" xml:lang="en">DSA-653</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13946/" xml:lang="en">13946</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19004" xml:lang="en">ethereal-x11-bo(19004)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-037.html" xml:lang="en">RHSA-2005:037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ethereal.com/appnotes/enpa-sa-00017.html" xml:lang="en">http://www.ethereal.com/appnotes/enpa-sa-00017.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/p-106.shtml" xml:lang="en">P-106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12326" xml:lang="en">12326</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" xml:lang="en">FLSA-2006:152922</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013" xml:lang="en">MDKSA-2005:013</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9140" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9140" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the X11 dissector in Ethereal 0.8.10 through 0.10.8 allows remote attackers to execute arbitrary code via a crafted packet.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0085">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:htdig:htdig:3.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:htdig:htdig:3.1.5_7"/>
        <cpe-lang:fact-ref name="cpe:/a:htdig:htdig:3.1.5_8"/>
        <cpe-lang:fact-ref name="cpe:/a:htdig:htdig:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:htdig:htdig:3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:htdig:htdig:3.2.0b2"/>
        <cpe-lang:fact-ref name="cpe:/a:htdig:htdig:3.2.0b3"/>
        <cpe-lang:fact-ref name="cpe:/a:htdig:htdig:3.2.0b4"/>
        <cpe-lang:fact-ref name="cpe:/a:htdig:htdig:3.2.0b5"/>
        <cpe-lang:fact-ref name="cpe:/a:htdig:htdig:3.2.0b6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.0"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.0::amd64"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.1"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.1::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:fedora_core:core_3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.0::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.1"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.2"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.0::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.1"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:10.0::amd64</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:10.1</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:10.1::x86_64</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:8.1</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1::x86_64</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.2</vuln:product>
      <vuln:product>cpe:/o:redhat:fedora_core:core_3.0</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1</vuln:product>
      <vuln:product>cpe:/a:htdig:htdig:3.2.0b2</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.1</vuln:product>
      <vuln:product>cpe:/a:htdig:htdig:3.2.0b6</vuln:product>
      <vuln:product>cpe:/a:htdig:htdig:3.2.0b4</vuln:product>
      <vuln:product>cpe:/a:htdig:htdig:3.1.5</vuln:product>
      <vuln:product>cpe:/a:htdig:htdig:3.2.0b3</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0::x86_64</vuln:product>
      <vuln:product>cpe:/a:htdig:htdig:3.2.0b5</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.0::x86_64</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:8.0</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:8.0::i386</vuln:product>
      <vuln:product>cpe:/a:htdig:htdig:3.1.6</vuln:product>
      <vuln:product>cpe:/a:htdig:htdig:3.2.0</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.0</vuln:product>
      <vuln:product>cpe:/a:htdig:htdig:3.1.5_8</vuln:product>
      <vuln:product>cpe:/a:htdig:htdig:3.1.5_7</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:8.2</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:10.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0085</vuln:cve-id>
    <vuln:published-datetime>2005-04-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:27.857-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10878" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10878" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12442" xml:lang="en">12442</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-680" xml:lang="en">DSA-680</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19223" xml:lang="en">htdig-config-xss(19223)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-073.html" xml:lang="en">RHSA-2005:073</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200502-16.xml" xml:lang="en">GLSA-200502-16</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013078" xml:lang="en">1013078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-090.html" xml:lang="en">RHSA-2005:090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00002.html" xml:lang="en">FLSA-2006:152907</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:063" xml:lang="en">MDKSA-2005:063</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/17415" xml:lang="en">17415</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/17414" xml:lang="en">17414</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/15007" xml:lang="en">15007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14795" xml:lang="en">14795</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14303" xml:lang="en">14303</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14276" xml:lang="en">14276</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14255" xml:lang="en">14255</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.46/SCOSA-2005.46.txt" xml:lang="en">SCOSA-2005.46</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10878" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10878" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0086">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::advanced_servers"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:3.0</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::workstation</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::advanced_servers</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0086</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:27.997-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T22:40:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11027" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11027" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=145527" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=145527</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://bugzilla.fedora.us/show_bug.cgi?id=2404" xml:lang="en">FLSA:2404</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19131" xml:lang="en">less-file-bo(19131)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-068.html" xml:lang="en">RHSA-2005:068</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11027" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11027" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file, as demonstrated using the UTF-8 locale.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0087">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:alsa:alsa-lib:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::desktop"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::workstation"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::advanced_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:alsa:alsa-lib:1.0.6</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::desktop</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::workstation</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0087</vuln:cve-id>
    <vuln:published-datetime>2005-04-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:28.153-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10355" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10355" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-033.html" xml:lang="en">RHSA-2005:033</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10355" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10355" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The alsa-lib package in Red Hat Linux 4 disables stack protection for the libasound.so library, which makes it easier for attackers to execute arbitrary code if there are other vulnerabilities in the library.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0088">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:1.9a"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.7.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_python:2.7.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:mod_python:2.7.4</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.6.1</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.7.1</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.3</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.1</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.4</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.6.3</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.7</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.7.3</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:1.9a</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.7.8</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.6.4</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.7.5</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.5</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.7.6</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.7.2</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.2</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.7.7</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.0</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.4.1</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.6</vuln:product>
      <vuln:product>cpe:/a:apache:mod_python:2.6.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0088</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:28.280-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T22:46:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10617" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10617" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/356409" xml:lang="en">VU#356409</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-689" xml:lang="en">DSA-689</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200502-14.xml" xml:lang="en">GLSA-200502-14</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2005/0003/" xml:lang="en">2005-0003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12519" xml:lang="en">12519</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/430286/100/0/threaded" xml:lang="en">FLSA:152896</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-104.html" xml:lang="en">RHSA-2005:104</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-100.html" xml:lang="en">RHSA-2005:100</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013156" xml:lang="en">1013156</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110815313218389&amp;w=2" xml:lang="en">20050211 [USN-80-1] mod_python vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000926" xml:lang="en">CLA-2005:926</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10617" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10617" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The publisher handler for mod_python 2.7.8 and earlier allows remote attackers to obtain access to restricted objects via a crafted URL.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0089">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:python_software_foundation:python:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:python_software_foundation:python:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:python_software_foundation:python:2.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:python_software_foundation:python:2.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:python_software_foundation:python:2.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:python_software_foundation:python:2.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:python_software_foundation:python:2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:python_software_foundation:python:2.2</vuln:product>
      <vuln:product>cpe:/a:python_software_foundation:python:2.4</vuln:product>
      <vuln:product>cpe:/a:python_software_foundation:python:2.3.2</vuln:product>
      <vuln:product>cpe:/a:python_software_foundation:python:2.3.1</vuln:product>
      <vuln:product>cpe:/a:python_software_foundation:python:2.3.4</vuln:product>
      <vuln:product>cpe:/a:python_software_foundation:python:2.3.3</vuln:product>
      <vuln:product>cpe:/a:python_software_foundation:python:2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0089</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:28.420-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T22:54:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9811" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9811" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.python.org/security/PSF-2005-001/" xml:lang="en">http://www.python.org/security/PSF-2005-001/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-666" xml:lang="en">DSA-666</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://python.org/security/PSF-2005-001/patch-2.2.txt" xml:lang="en">http://python.org/security/PSF-2005-001/patch-2.2.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746469728728&amp;w=2" xml:lang="en">20050203 Python Security Advisory PSF-2005-001 - SimpleXMLRPCServer.py</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19217" xml:lang="en">python-simplexmlrpcserver-bypass(19217)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2005/0003/" xml:lang="en">2005-0003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-108.html" xml:lang="en">RHSA-2005:108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12437" xml:lang="en">12437</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:035" xml:lang="en">MDKSA-2005:035</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013083" xml:lang="en">1013083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14128" xml:lang="en">14128</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9811" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9811" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0090">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:4.0</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::advanced_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::workstation</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0090</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:28.547-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T23:00:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10425" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10425" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/20618" xml:lang="en">red-hat-regression-dos(20618)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12599" xml:lang="en">12599</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-092.html" xml:lang="en">RHSA-2005:092</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10425" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10425" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>A regression error in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch omits an "access check," which allows local users to cause a denial of service (crash).</vuln:summary>
  </entry>
  <entry id="CVE-2005-0091">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:4.0</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::advanced_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::workstation</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0091</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:28.670-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-02T23:03:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11249" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11249" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/20619" xml:lang="en">red-hat-patch-gain-privileges(20619)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12599" xml:lang="en">12599</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-092.html" xml:lang="en">RHSA-2005:092</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11249" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11249" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when using the hugemem kernel, allows local users to read and write to arbitrary kernel memory and gain privileges via certain syscalls.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0092">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:4.0</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::advanced_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::workstation</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0092</vuln:cve-id>
    <vuln:published-datetime>2005-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:28.810-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T00:17:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11647" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11647" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12599" xml:lang="en">12599</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-092.html" xml:lang="en">RHSA-2005:092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/20620" xml:lang="en">red-hat-patch-dos(20620)</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11647" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11647" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when running on x86 with the hugemem kernel, allows local users to cause a denial of service (crash).</vuln:summary>
  </entry>
  <entry id="CVE-2005-0093">
    <vuln:cve-id>CVE-2005-0093</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:55.353-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0094">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.0_patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1_patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable7"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_stable7"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable7"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable9"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.6.stable1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squid:squid:2.5.6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.1_patch2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3_.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3_.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable7</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4_.stable7</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.0_patch2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4_.stable6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4_stable7</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_stable9</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4_.stable2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3_stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.6.stable1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0094</vuln:cve-id>
    <vuln:published-datetime>2005-01-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:28.967-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T00:28:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11146" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11146" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-061.html" xml:lang="en">RHSA-2005:061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-060.html" xml:lang="en">RHSA-2005:060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-651" xml:lang="en">DSA-651</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200501-25.xml" xml:lang="en">GLSA-200501-25</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13825" xml:lang="en">13825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2005/0003/" xml:lang="en">2005-0003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-gopher_html_parsing.patch" xml:lang="en">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-gopher_html_parsing.patch</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/Advisories/SQUID-2005_1.txt" xml:lang="en">http://www.squid-cache.org/Advisories/SQUID-2005_1.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2005_06_squid.html" xml:lang="en">SUSE-SA:2005:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923" xml:lang="en">CLA-2005:923</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12276" xml:lang="en">12276</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:014" xml:lang="en">MDKSA-2005:014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/updates/FEDORA--.shtml" xml:lang="en">FLSA-2006:152809</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11146" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11146" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0095">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.0_patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1_patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable7"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_stable7"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable7"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable9"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.6.stable1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squid:squid:2.5.6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.1_patch2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3_.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3_.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable7</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4_.stable7</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.0_patch2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4_.stable6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4_stable7</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_stable9</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4_.stable2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3_stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.6.stable1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0095</vuln:cve-id>
    <vuln:published-datetime>2005-01-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:29.093-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T00:42:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10269" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10269" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2005/0003/" xml:lang="en">2005-0003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/Advisories/SQUID-2005_2.txt" xml:lang="en">http://www.squid-cache.org/Advisories/SQUID-2005_2.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-061.html" xml:lang="en">RHSA-2005:061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-060.html" xml:lang="en">RHSA-2005:060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2005_06_squid.html" xml:lang="en">SUSE-SA:2005:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-651" xml:lang="en">DSA-651</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200501-25.xml" xml:lang="en">GLSA-200501-25</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13825" xml:lang="en">13825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923" xml:lang="en">CLA-2005:923</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_denial_of_service.patch" xml:lang="en">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_denial_of_service.patch</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12275" xml:lang="en">12275</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/12886" xml:lang="en">12886</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:014" xml:lang="en">MDKSA-2005:014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012882" xml:lang="en">1012882</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/updates/FEDORA--.shtml" xml:lang="en">FLSA-2006:152809</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10269" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10269" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCCP messages with source addresses that are spoofed to reference Squid's home router and invalid WCCP_I_SEE_YOU cache numbers.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0096">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.0_patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1_patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable7"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_stable7"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable7"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable9"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.6.stable1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squid:squid:2.5.6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.1_patch2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3_.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3_.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable7</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4_.stable7</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.0_patch2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4_.stable6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4_stable7</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_stable9</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4_.stable2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3_stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.6.stable1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0096</vuln:cve-id>
    <vuln:published-datetime>2005-01-25T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:29.217-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T00:50:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10233" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10233" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth" xml:lang="en">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-061.html" xml:lang="en">RHSA-2005:061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-060.html" xml:lang="en">RHSA-2005:060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200501-25.xml" xml:lang="en">GLSA-200501-25</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923" xml:lang="en">CLA-2005:923</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2005/0003/" xml:lang="en">2005-0003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2005_06_squid.html" xml:lang="en">SUSE-SA:2005:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12324" xml:lang="en">12324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012818" xml:lang="en">1012818</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/updates/FEDORA--.shtml" xml:lang="en">FLSA-2006:152809</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10233" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10233" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (memory consumption).</vuln:summary>
  </entry>
  <entry id="CVE-2005-0097">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.0_patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1_patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3_stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_.stable7"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4_stable7"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable7"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable9"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.6.stable1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squid:squid:2.5.6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.1_patch2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3_.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3_.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable7</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4_.stable7</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.0_patch2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4_.stable6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4_stable7</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_stable9</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4_.stable2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3_stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.6.stable1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0097</vuln:cve-id>
    <vuln:published-datetime>2005-01-11T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:29.343-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T01:17:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11646" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11646" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2005/0003/" xml:lang="en">2005-0003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth" xml:lang="en">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-061.html" xml:lang="en">RHSA-2005:061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-060.html" xml:lang="en">RHSA-2005:060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2005_06_squid.html" xml:lang="en">SUSE-SA:2005:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200501-25.xml" xml:lang="en">GLSA-200501-25</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13789" xml:lang="en">13789</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12220" xml:lang="en">12220</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012818" xml:lang="en">1012818</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/updates/FEDORA--.shtml" xml:lang="en">FLSA-2006:152809</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11646" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11646" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0098">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:abuse:abuse-sdl:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:abuse:abuse-sdl:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0098</vuln:cve-id>
    <vuln:published-datetime>2005-03-08T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:18.823-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T01:25:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-691" xml:lang="en">DSA-691</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14495" xml:lang="en">14495</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in the SDL port of abuse (abuse-SDL) before 2.00 allow local users to execute arbitrary code via the command line.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0099">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:abuse:abuse-sdl:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:abuse:abuse-sdl:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0099</vuln:cve-id>
    <vuln:published-datetime>2005-03-08T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:18.980-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T01:32:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-691" xml:lang="en">DSA-691</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14495" xml:lang="en">14495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/14610" xml:lang="en">14610</vuln:reference>
    </vuln:references>
    <vuln:summary>The SDL port of abuse (abuse-SDL) before 2.00 does not properly drop privileges before creating certain files, which allows local users to create or overwrite arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0100">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:emacs:21.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:emacs:20.0"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:xemacs:21.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:emacs:20.0</vuln:product>
      <vuln:product>cpe:/a:gnu:xemacs:21.4</vuln:product>
      <vuln:product>cpe:/a:gnu:emacs:21.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0100</vuln:cve-id>
    <vuln:published-datetime>2005-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:29.653-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T01:40:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9408" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9408" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19246" xml:lang="en">xemacs-movemail-format-string(19246)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-133.html" xml:lang="en">RHSA-2005:133</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-112.html" xml:lang="en">RHSA-2005:112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-110.html" xml:lang="en">RHSA-2005:110</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-685" xml:lang="en">DSA-685</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-671" xml:lang="en">DSA-671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-670" xml:lang="en">DSA-670</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780416112719&amp;w=2" xml:lang="en">20050207 [USN-76-1] Emacs vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12462" xml:lang="en">12462</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/433928/30/5010/threaded" xml:lang="en">FLSA-2006:152898</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:038" xml:lang="en">MDKSA-2005:038</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9408" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9408" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0101">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:newspost:newspost:2.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:newspost:newspost:2.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0101</vuln:cve-id>
    <vuln:published-datetime>2005-02-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:19.277-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T02:00:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200502-05.xml" xml:lang="en">GLSA-200502-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19178" xml:lang="en">newspost-socketgetline-bo(19178)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vuxml.org/freebsd/7f13607b-6948-11d9-8937-00065be4b5b6.html" xml:lang="en">http://www.vuxml.org/freebsd/7f13607b-6948-11d9-8937-00065be4b5b6.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14092/" xml:lang="en">14092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://people.freebsd.org/~niels/issues/newspost-20050114.txt" xml:lang="en">http://people.freebsd.org/~niels/issues/newspost-20050114.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746336728781&amp;w=2" xml:lang="en">20050202 RE: SECURITEY.NNOV.RU NewsPost buffer overflow [EXPLOIT]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12418" xml:lang="en">12418</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013056" xml:lang="en">1013056</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14098" xml:lang="en">14098</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the socket_getline function in Newspost 2.1.1 and earlier allows remote malicious NNTP servers to execute arbitrary code via a long string without a newline character.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0102">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ximian:evolution:1.3.2_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ximian:evolution:1.2.3</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2.4</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.2.2</vuln:product>
      <vuln:product>cpe:/a:ximian:evolution:1.3.2_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0102</vuln:cve-id>
    <vuln:published-datetime>2005-01-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:29.903-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T02:09:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9616" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9616" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19031" xml:lang="en">evolution-camellockhelper-bo(19031)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12354" xml:lang="en">12354</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-397.html" xml:lang="en">RHSA-2005:397</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-673" xml:lang="en">DSA-673</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200501-35.xml" xml:lang="en">GLSA-200501-35</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000925" xml:lang="en">CLA-2005:925</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-238.html" xml:lang="en">RHSA-2005:238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntulinux.org/support/documentation/usn/usn-69-1" xml:lang="en">USN-69-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:024" xml:lang="en">MDKSA-2005:024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012981" xml:lang="en">1012981</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13830" xml:lang="en">13830</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9616" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9616" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0103">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3a</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.0.5</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.6</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3_rc1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.0.4</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.2</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.4</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.5</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.8</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.0</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.0</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.11</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.7</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.2</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.9</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.10</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0103</vuln:cve-id>
    <vuln:published-datetime>2005-01-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T02:31:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10670" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10670" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squirrelmail.org/security/issue/2005-01-19?PHPSESSID=8af117822fb1ca3aa966a64248b5d223" xml:lang="en">http://www.squirrelmail.org/security/issue/2005-01-19?PHPSESSID=8af117822fb1ca3aa966a64248b5d223</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-135.html" xml:lang="en">RHSA-2005:135</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-099.html" xml:lang="en">RHSA-2005:099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13962/" xml:lang="en">13962</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" xml:lang="en">APPLE-SA-2005-03-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19037" xml:lang="en">squirrelmail-frame-file-include(19037)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml" xml:lang="en">GLSA-200501-39</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2" xml:lang="en">20050129 SquirrelMail Security Advisory</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10670" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10670" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by modifying a URL parameter to reference a URL on a remote web server that contains the code.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0104">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3a"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.44"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3a</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.0.5</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.6</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3_rc1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.0.4</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.44</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.2</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.4</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.5</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.8</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.0</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.0</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.11</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.7</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.2</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.9</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.10</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0104</vuln:cve-id>
    <vuln:published-datetime>2005-01-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:30.153-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T02:41:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10568" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10568" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squirrelmail.org/security/issue/2005-01-20" xml:lang="en">http://www.squirrelmail.org/security/issue/2005-01-20</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-135.html" xml:lang="en">RHSA-2005:135</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-099.html" xml:lang="en">RHSA-2005:099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-662" xml:lang="en">DSA-662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14096" xml:lang="en">14096</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13962/" xml:lang="en">13962</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2" xml:lang="en">20050129 SquirrelMail Security Advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" xml:lang="en">APPLE-SA-2005-03-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19036" xml:lang="en">squirrelmail-webmailphp-xss(19036)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml" xml:lang="en">GLSA-200501-39</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10568" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10568" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to inject arbitrary web script or HTML via certain integer variables.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0105">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:typespeed:typespeed:0.4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:typespeed:typespeed:0.4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0105</vuln:cve-id>
    <vuln:published-datetime>2005-02-16T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:20.010-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T03:11:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-684" xml:lang="en">DSA-684</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0106">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.04"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.04</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0106</vuln:cve-id>
    <vuln:published-datetime>2005-05-03T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-11-13T00:39:05.670-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-12T15:05:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntulinux.org/support/documentation/usn/usn-113-1" xml:lang="en">USN-113-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/13471" xml:lang="en">13471</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:023" xml:lang="en">MDKSA-2006:023</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18639" xml:lang="en">18639</vuln:reference>
    </vuln:references>
    <vuln:summary>SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0107">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:debian:bsmtpd:2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:debian:bsmtpd:2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0107</vuln:cve-id>
    <vuln:published-datetime>2005-02-25T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:20.323-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T03:24:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-690" xml:lang="en">DSA-690</vuln:reference>
    </vuln:references>
    <vuln:summary>bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0108">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_auth_radius:1.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:mod_auth_radius:1.5.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0108</vuln:cve-id>
    <vuln:published-datetime>2005-01-11T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:20.480-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T03:41:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18841" xml:lang="en">modauthradius-dos(18841)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-659" xml:lang="en">DSA-659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-02" xml:lang="en">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548193312050&amp;w=2" xml:lang="en">20050111 Apache mod_auth_radius remote integer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12217" xml:lang="en">12217</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012829" xml:lang="en">1012829</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14046" xml:lang="en">14046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13773" xml:lang="en">13773</vuln:reference>
    </vuln:references>
    <vuln:summary>Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0109">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.4:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:1.1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.0:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.5.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.5.1:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.5:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.0:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.1.1:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.10:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.10:release_p8"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.10:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.11:release_p3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.11:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.11:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.2:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:release_p38"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.3:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4:release_p42"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.4:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:release_p32"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.5:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:release_p20"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.6:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:release_p17"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.7:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8:pre-release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8:release_p6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.8:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.9:pre-release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.9:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0:release_p14"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:release_p5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2.1:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.3:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.3:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.3:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.4:pre-release"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::workstation_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:fedora_core:core_3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.1.3_up"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0:x86_update_2"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:4.1::ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:4.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.04::amd64"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.04::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.04::powerpc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation_ia64</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6.2</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.5:stable</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::workstation_server</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0:x86_update_2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:stable</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:7.1.3_up</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:7.1.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:release_p38</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1.1:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.0:releng</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server_ia64</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.6.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.9</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.0:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:release_p32</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:4.1::ppc</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.2:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3:release</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:7.1.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0:release_p14</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::advanced_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6</vuln:product>
      <vuln:product>cpe:/o:redhat:fedora_core:core_3.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:10.0::sparc</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:stable</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.9:releng</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9.0::x86</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8:pre-release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.10</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.04::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:3.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.5.1:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.8:release_p6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0::x86</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.2.1:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.5.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.11:release_p3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.9:pre-release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.5.1:stable</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:4.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.11:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7:release_p17</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.2</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.3:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1:release</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4:release_p42</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.10:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1.1:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.11:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.4:pre-release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1:alpha</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:releng</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server_ia64</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.10:release_p8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:4.1::ia64</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.2</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.04::powerpc</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:1.1.5.1</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::advanced_server</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.10:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.7.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1:release_p5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.3:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.6:release_p20</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0:alpha</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.3:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.5:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.04::amd64</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.1.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.2.1:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.0:alpha</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0109</vuln:cve-id>
    <vuln:published-datetime>2005-03-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:32.907-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T03:59:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9747" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9747" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/911878" xml:lang="en">VU#911878</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12724" xml:lang="en">12724</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013967" xml:lang="en">1013967</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2005/3002" xml:lang="en">ADV-2005-3002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2005/0540" xml:lang="en">ADV-2005-0540</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-800.html" xml:lang="en">RHSA-2005:800</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-476.html" xml:lang="en">RHSA-2005:476</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.daemonology.net/papers/htt.pdf" xml:lang="en">http://www.daemonology.net/papers/htt.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.daemonology.net/hyperthreading-considered-harmful/" xml:lang="en">http://www.daemonology.net/hyperthreading-considered-harmful/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=isg1SSRVHMCHMC_C081516_754" xml:lang="en">http://www-1.ibm.com/support/docview.wss?uid=isg1SSRVHMCHMC_C081516_754</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101739-1" xml:lang="en">101739</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18165" xml:lang="en">18165</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/15348" xml:lang="en">15348</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=openbsd-misc&amp;m=110995101417256&amp;w=2" xml:lang="en">[openbsd-misc] 20050304 Re: FreeBSD hiding security stuff</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=freebsd-security&amp;m=110994370429609&amp;w=2" xml:lang="en">[freebsd-security] 20050304 [Fwd: Re: FW:FreeBSD hiding security stuff]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=freebsd-hackers&amp;m=110994026421858&amp;w=2" xml:lang="en">[freebsd-hackers] 20050304 Re: FW:FreeBSD hiding security stuff</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.24/SCOSA-2005.24.txt" xml:lang="en">SCOSA-2005.24</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9747" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9747" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0110">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0110</vuln:cve-id>
    <vuln:published-datetime>2005-01-14T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:21.107-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T04:22:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110569119106172&amp;w=2" xml:lang="en">20050114 Internet Explorer (SP2) - Remote File Download</vuln:reference>
    </vuln:references>
    <vuln:summary>Internet Explorer 6 on Windows XP SP2 allows remote attackers to bypass the file download warning dialog and possibly trick an unknowledgeable user into executing arbitrary code via a web page with a body element containing an onclick tag, as demonstrated using the createElement function.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0111">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mysql:maxdb:7.5.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mysql:maxdb:7.5.00</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0111</vuln:cve-id>
    <vuln:published-datetime>2005-01-13T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:33.097-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T04:28:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=181&amp;type=vulnerabilities" xml:lang="en">20050113 MySQL MaxDB WebAgent websql logon Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12265" xml:lang="en">12265</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012893" xml:lang="en">1012893</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0112">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:3com:3crwe454g72:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/h:3com:3crwe454g72:1.0.2.11"/>
        <cpe-lang:fact-ref name="cpe:/h:3com:3crwe454g72:1.0.3.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:3com:3crwe454g72:1.0.3.5</vuln:product>
      <vuln:product>cpe:/h:3com:3crwe454g72:1.0.2.11</vuln:product>
      <vuln:product>cpe:/h:3com:3crwe454g72:1.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0112</vuln:cve-id>
    <vuln:published-datetime>2005-04-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:21.417-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18994" xml:lang="en">3com-officeconnect-information-disclosure(18994)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12322" xml:lang="en">12322</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=188&amp;type=vulnerabilities" xml:lang="en">20050120 3Com OfficeConnect Wireless 11g AP Information Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012958" xml:lang="en">1012958</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13942" xml:lang="en">13942</vuln:reference>
    </vuln:references>
    <vuln:summary>The web-based administrative interface for 3Com OfficeConnect Wireless 11g Access Point (AP) 1.00.08, and possibly earlier versions before 1.03.07A, allows remote attackers to bypass authentication and obtain sensitive information by directly accessing the (1) config.bin (2) profile.wlp?PN=ggg or (3) event.logs URLs.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0113">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0113</vuln:cve-id>
    <vuln:published-datetime>2005-01-14T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:21.590-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T04:44:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18894" xml:lang="en">irix-inpview-gain-privileges(18894)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=182&amp;type=vulnerabilities" xml:lang="en">20050113 SGI IRIX inpview Design Error Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13858" xml:lang="en">13858</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12259" xml:lang="en">12259</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/12915" xml:lang="en">12915</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012894" xml:lang="en">1012894</vuln:reference>
    </vuln:references>
    <vuln:summary>inpview in SGI IRIX allows local users to execute arbitrary commands via the SUN_TTSESSION_CMD environment variable, which is executed by inpview without dropping privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0114">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:checkpoint:check_point_integrity_client:4.5.122.000"/>
        <cpe-lang:fact-ref name="cpe:/a:zonelabs:zonealarm:5.5.062.011"/>
        <cpe-lang:fact-ref name="cpe:/a:checkpoint:check_point_integrity_client:5.1.556.166"/>
        <cpe-lang:fact-ref name="cpe:/a:zonelabs:zonealarm_wireless_security:5.5.080.000"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:zonelabs:zonealarm:5.5.062.011</vuln:product>
      <vuln:product>cpe:/a:checkpoint:check_point_integrity_client:5.1.556.166</vuln:product>
      <vuln:product>cpe:/a:checkpoint:check_point_integrity_client:4.5.122.000</vuln:product>
      <vuln:product>cpe:/a:zonelabs:zonealarm_wireless_security:5.5.080.000</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0114</vuln:cve-id>
    <vuln:published-datetime>2005-02-11T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:21.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T05:03:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=199&amp;type=vulnerabilities" xml:lang="en">20050211 ZoneAlarm 5.1 Invalid Pointer Dereference Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://download.zonelabs.com/bin/free/securityAlert/19.html" xml:lang="en">http://download.zonelabs.com/bin/free/securityAlert/19.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12531" xml:lang="en">12531</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14256" xml:lang="en">14256</vuln:reference>
    </vuln:references>
    <vuln:summary>vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Client 4.x before 4.5.122.000 and 5.x before 5.1.556.166 do not properly verify that the ServerPortName argument to the NtConnectPort function is a valid memory address, which allows local users to cause a denial of service (system crash) when ZoneAlarm attempts to dereference an invalid pointer.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0115">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:datarescue:ida:4.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:datarescue:ida:4.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0115</vuln:cve-id>
    <vuln:published-datetime>2005-01-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:21.903-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T05:24:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19042" xml:lang="en">database-ida-portable-executable-bo(19042)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.datarescue.com/ubb/ultimatebb.php?/topic/2/146.html" xml:lang="en">http://www.datarescue.com/ubb/ultimatebb.php?/topic/2/146.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=189&amp;type=vulnerabilities" xml:lang="en">20050124 DataRescue Interactive Disassembler Pro Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12353" xml:lang="en">12353</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012975" xml:lang="en">1012975</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13980" xml:lang="en">13980</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in DataRescue Interactive Disassembler (IDA) Pro 4.7 allows attackers to execute arbitrary code via a PE file with an Import Address Table containing a long import library name.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0116">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:awstats:awstats:6.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:awstats:awstats:6.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0116</vuln:cve-id>
    <vuln:published-datetime>2005-01-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:22.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T05:41:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/272296" xml:lang="en">VU#272296</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=185&amp;type=vulnerabilities&amp;flashstatus=false" xml:lang="en">20050117 AWStats Remote Command Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13893/" xml:lang="en">13893</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://awstats.sourceforge.net/docs/awstats_changelog.txt" xml:lang="en">http://awstats.sourceforge.net/docs/awstats_changelog.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12298" xml:lang="en">12298</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/13002" xml:lang="en">13002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://packetstormsecurity.org/0501-exploits/AWStatsVulnAnalysis.pdf" xml:lang="en">http://packetstormsecurity.org/0501-exploits/AWStatsVulnAnalysis.pdf</vuln:reference>
    </vuln:references>
    <vuln:summary>AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0117">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xshisen:xshisen:1.36"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xshisen:xshisen:1.36</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0117</vuln:cve-id>
    <vuln:published-datetime>2005-01-11T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:22.213-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T05:56:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vuxml.org/freebsd/56971fa6-641c-11d9-a097-000854d03344.html" xml:lang="en">http://www.vuxml.org/freebsd/56971fa6-641c-11d9-a097-000854d03344.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=289784" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=289784</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in XShisen before 1.36 allows local users to execute arbitrary code via a long GECOS field.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0118">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:helvis:helvis:1.8h2_1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:helvis:helvis:1.8h2_1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0118</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:22.370-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T10:13:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vuxml.org/freebsd/bb99f803-5fde-11d9-b721-00065be4b5b6.html" xml:lang="en">http://www.vuxml.org/freebsd/bb99f803-5fde-11d9-b721-00065be4b5b6.html</vuln:reference>
    </vuln:references>
    <vuln:summary>helvis 1.8h2_1 and earlier stores recovery files in world readable directories with world readable permissions, which allows local users to read the recovered files of other users.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0119">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:helvis:helvis:1.8h2_1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:helvis:helvis:1.8h2_1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0119</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:22.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T10:14:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vuxml.org/freebsd/bb99f803-5fde-11d9-b721-00065be4b5b6.html" xml:lang="en">http://www.vuxml.org/freebsd/bb99f803-5fde-11d9-b721-00065be4b5b6.html</vuln:reference>
    </vuln:references>
    <vuln:summary>helvis 1.8h2_1 and earlier allows local users to recover and read the files of other users via the elvrec setuid program.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0120">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:helvis:helvis:1.8h2_1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2005-0120</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:22.683-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T10:16:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://people.freebsd.org/~niels/ports/korean/helvis/issues.txt" xml:lang="en">http://people.freebsd.org/~niels/ports/korean/helvis/issues.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>helvis 1.8h2_1 and earlier allows local users to delete arbitrary files via the elvprsv setuid program.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0121">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:alexander_siegel:golddig:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:alexander_siegel:golddig:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0121</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:22.840-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T10:18:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vuxml.org/freebsd/949c470e-528f-11d9-ac20-00065be4b5b6.html" xml:lang="en">http://www.vuxml.org/freebsd/949c470e-528f-11d9-ac20-00065be4b5b6.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19040" xml:lang="en">golddig-long-username-bo(19040)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19039" xml:lang="en">golddig-long-mapname-bo(19039)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in golddig 2.0 and earlier allow local users to execute arbitrary code via (1) a long map name command line argument or (2) a long username as recorded in the USER environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0122">
    <vuln:cve-id>CVE-2005-0122</vuln:cve-id>
    <vuln:published-datetime>2005-04-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:59.617-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0975.  Reason: This candidate is a duplicate of CVE-2005-0975.  Notes: All CVE users should reference CVE-2005-0975 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0124">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22:pre10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23:pre9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23_ow2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24_ow1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.29:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.29:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:2.6.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.22:pre10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.24_ow1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23:pre9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.29:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:2.6.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.29:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18::x86</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23_ow2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3:pre3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0124</vuln:cve-id>
    <vuln:published-datetime>2005-04-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:34.017-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11690" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11690" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2005/1878" xml:lang="en">ADV-2005-1878</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://seclists.org/lists/linux-kernel/2005/Jan/2020.html" xml:lang="en">[linux-kernel] 20050107 [PATCH 2.6.10-mm2] fs/coda Re: [Coverity] Untrusted user data in kernel</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://seclists.org/lists/linux-kernel/2005/Jan/2018.html" xml:lang="en">[linux-kernel] 20050107 [PATCH 2.4.29-pre3-bk4] fs/coda Re: [Coverity] Untrusted user data in kernel</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://seclists.org/lists/linux-kernel/2005/Jan/1089.html" xml:lang="en">[linux-kernel] 20050105 Re: [Coverity] Untrusted user data in kernel</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://seclists.org/lists/linux-kernel/2004/Dec/3914.html" xml:lang="en">[linux-kernel] 20041216 [Coverity] Untrusted user data in kernel</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/14967" xml:lang="en">14967</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/428028/100/0/threaded" xml:lang="en">FLSA:157459-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2006-0191.html" xml:lang="en">RHSA-2006:0191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-663.html" xml:lang="en">RHSA-2005:663</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1082" xml:lang="en">DSA-1082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1070" xml:lang="en">DSA-1070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1069" xml:lang="en">DSA-1069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1067" xml:lang="en">DSA-1067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1017" xml:lang="en">DSA-1017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013018" xml:lang="en">1013018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20338" xml:lang="en">20338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20202" xml:lang="en">20202</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20163" xml:lang="en">20163</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19374" xml:lang="en">19374</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18684" xml:lang="en">18684</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/17002" xml:lang="en">17002</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11690" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11690" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The coda_pioctl function in the coda functionality (pioctl.c) for Linux kernel 2.6.9 and 2.4.x before 2.4.29 may allow local users to cause a denial of service (crash) or execute arbitrary code via negative vi.in_size or vi.out_size values, which may trigger a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0125">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0125</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:34:59.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T10:47:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/678150" xml:lang="en">VU#678150</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html" xml:lang="en">APPLE-SA-2005-01-25</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18981" xml:lang="en">macos-at-gain-privileges(18981)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitalmunition.com/DMA%5B2005-0127a%5D.txt" xml:lang="en">http://www.digitalmunition.com/DMA[2005-0127a].txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110685027017411&amp;w=2" xml:lang="en">20050127 DMA[2005-0127a] - 'Apple OSX batch family poor use of setuid'</vuln:reference>
    </vuln:references>
    <vuln:summary>The "at" commands on Mac OS X 10.3.7 and earlier do not properly drop privileges, which allows local users to (1) delete arbitrary files via atrm, (2) execute arbitrary programs via the -f argument to batch, or (3) read arbitrary files via the -f argument to batch, which generates a job file that is readable by the local user.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0126">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0126</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:23.573-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T10:52:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/980078" xml:lang="en">VU#980078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19083" xml:lang="en">macos-icc-profile-bo(19083)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html" xml:lang="en">APPLE-SA-2005-01-25</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12367" xml:lang="en">12367</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013000" xml:lang="en">1013000</vuln:reference>
    </vuln:references>
    <vuln:summary>ColorSync on Mac OS X 10.3.7 and 10.3.8 allows attackers to execute arbitrary code via malformed ICC color profiles that modify the heap.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0127">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0127</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:23.730-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T10:55:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/464662" xml:lang="en">VU#464662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19085" xml:lang="en">macos-ethernet-address-disclosure(19085)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14005" xml:lang="en">14005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html" xml:lang="en">APPLE-SA-2005-01-25</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013001" xml:lang="en">1013001</vuln:reference>
    </vuln:references>
    <vuln:summary>Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes information that identifies the Ethernet hardware being used, which allows remote attackers to link mail messages to a particular machine.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0129">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:berlios:konversation:0.15"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:berlios:konversation:0.15</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0129</vuln:cve-id>
    <vuln:published-datetime>2005-04-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:23.887-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110626383310742&amp;w=2" xml:lang="en">20050119 Multiple vulnerabilities in Konversation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19025" xml:lang="en">konversation-expansion-execute-code(19025)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031033.html" xml:lang="en">20050119 Multiple vulnerabilities in Konversation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12312" xml:lang="en">12312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kde.org/info/security/advisory-20050121-1.txt" xml:lang="en">http://www.kde.org/info/security/advisory-20050121-1.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-34.xml" xml:lang="en">GLSA-200501-34</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012972" xml:lang="en">1012972</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13989" xml:lang="en">13989</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13919" xml:lang="en">13919</vuln:reference>
    </vuln:references>
    <vuln:summary>The Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel name containing "%" variables, which are recursively expanded by the Server::parseWildcards function when the Part Button is selected.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0130">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:berlios:konversation:0.15"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:berlios:konversation:0.15</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0130</vuln:cve-id>
    <vuln:published-datetime>2005-04-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:24.043-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110626383310742&amp;w=2" xml:lang="en">20050119 Multiple vulnerabilities in Konversation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19008" xml:lang="en">konversation-perlscript-execute-code(19008)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031033.html" xml:lang="en">20050119 Multiple vulnerabilities in Konversation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12312" xml:lang="en">12312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kde.org/info/security/advisory-20050121-1.txt" xml:lang="en">http://www.kde.org/info/security/advisory-20050121-1.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-34.xml" xml:lang="en">GLSA-200501-34</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012972" xml:lang="en">1012972</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13989" xml:lang="en">13989</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13919" xml:lang="en">13919</vuln:reference>
    </vuln:references>
    <vuln:summary>Certain Perl scripts in Konversation 0.15 allow remote attackers to execute arbitrary commands via shell metacharacters in (1) channel names or (2) song names that are not properly quoted when the user runs IRC sripts.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0131">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:berlios:konversation:0.15"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:berlios:konversation:0.15</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0131</vuln:cve-id>
    <vuln:published-datetime>2005-04-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:24.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110626383310742&amp;w=2" xml:lang="en">20050119 Multiple vulnerabilities in Konversation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19038" xml:lang="en">konversation-nick-password-information-disclosure(19038)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031033.html" xml:lang="en">20050119 Multiple vulnerabilities in Konversation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12312" xml:lang="en">12312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kde.org/info/security/advisory-20050121-1.txt" xml:lang="en">http://www.kde.org/info/security/advisory-20050121-1.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-34.xml" xml:lang="en">GLSA-200501-34</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012972" xml:lang="en">1012972</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13989" xml:lang="en">13989</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13919" xml:lang="en">13919</vuln:reference>
    </vuln:references>
    <vuln:summary>The Quick Connection dialog in Konversation 0.15 inadvertently uses the user-provided password as the nickname instead of the user-provided nickname when connecting to the IRC server, which could leak the password to other users.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0133">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.51"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.52"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.53"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.54"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.60"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.65"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.67"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.68"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.68.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.65</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.54</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.68</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.67</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.53</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.52</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.51</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.68.1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.60</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0133</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:35:00.180-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T11:10:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2005/0003/" xml:lang="en">2005-0003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-46.xml" xml:lang="en">GLSA-200501-46</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=300116" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=300116</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000928" xml:lang="en">CLA-2005:928</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:025" xml:lang="en">MDKSA-2005:025</vuln:reference>
    </vuln:references>
    <vuln:summary>ClamAV 0.80 and earlier allows remote attackers to cause a denial of service (clamd daemon crash) via a ZIP file with malformed headers.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0134">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sco:unixware:7.1.1</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:7.1.4</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:7.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0134</vuln:cve-id>
    <vuln:published-datetime>2005-05-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:34.687-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-18T10:30:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.8/SCOSA-2005.8.txt" xml:lang="en">SCOSA-2005.8</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2005/0077" xml:lang="en">ADV-2005-0077</vuln:reference>
    </vuln:references>
    <vuln:summary>The X server in SCO UnixWare 7.1.1, 7.1.3, and 7.1.4 does not properly create socket directories in /tmp, which could allow attackers to hijack local sockets.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0135">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0135</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:32.687-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T11:40:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9040" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9040" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=148868" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=148868</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-366.html" xml:lang="en">RHSA-2005:366</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-284.html" xml:lang="en">RHSA-2005:284</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/15019" xml:lang="en">15019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://linux.bkbits.net:8080/linux-2.6/cset@41f2beablXVnAs_6fznhhITh1j5hZg" xml:lang="en">http://linux.bkbits.net:8080/linux-2.6/cset@41f2beablXVnAs_6fznhhITh1j5hZg</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/13266" xml:lang="en">13266</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-293.html" xml:lang="en">RHSA-2005:293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1082" xml:lang="en">DSA-1082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1070" xml:lang="en">DSA-1070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1069" xml:lang="en">DSA-1069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1067" xml:lang="en">DSA-1067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20338" xml:lang="en">20338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20202" xml:lang="en">20202</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20163" xml:lang="en">20163</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9040" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9040" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The unw_unwind_to_user function in unwind.c on Itanium (ia64) architectures in Linux kernel 2.6 allows local users to cause a denial of service (system crash).</vuln:summary>
  </entry>
  <entry id="CVE-2005-0136">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1.5::386"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1.5::686"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1.5::686_smp"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1.5::amd64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1.5::amd64_k8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1.5::amd64_k8_smp"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1.5::amd64_xeon"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1.5::k7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1.5::k7_smp"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1.5::power3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1.5::power3_smp"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1.5::power4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1.5::power4_smp"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1.5::powerpc"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1.5::powerpc_smp"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:2.6.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:final"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:rc4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1.5::power4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1.5::amd64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1.5::amd64_xeon</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1.5::k7_smp</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1.5::386</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1.5::amd64_k8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1.5::686</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1.5::power3_smp</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:final</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1.5::powerpc_smp</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:2.6.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1.5::power4_smp</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1.5::k7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1.5::amd64_k8_smp</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1.5::686_smp</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1.5::powerpc</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1.5::power3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0136</vuln:cve-id>
    <vuln:discovered-datetime>2005-09-29T00:00:00.000-04:00</vuln:discovered-datetime>
    <vuln:published-datetime>2005-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:35.110-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-06-01T19:09:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11628" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11628" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=155283" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=155283</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=148862" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=148862</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-663.html" xml:lang="en">RHSA-2005:663</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-420.html" xml:lang="en">RHSA-2005:420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11" xml:lang="en">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.gelato.unsw.edu.au/archives/linux-ia64/0409/11073.html" xml:lang="en">[linux-ia64] 20040916 Re: [Patch] Per CPU MCA/INIT data save areas</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/17002" xml:lang="en">17002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://openvz.org/news/updates/kernel-022stab045.1-released" xml:lang="en">http://openvz.org/news/updates/kernel-022stab045.1-released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2005/1878" xml:lang="en">ADV-2005-1878</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.alioth.debian.org/pipermail/kernel-svn-changes/2005-August/002597.html" xml:lang="en">[kernel-svn-changes] 20050816 r3920 - in branches/dist/sarge-security: . kernel kernel/i386 kernel/source kernel/source/kernel-source-2.6.8-2.6.8/debian</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11628" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11628" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Linux kernel before 2.6.11 on the Itanium IA64 platform has certain "ptrace corner cases" that allow local users to cause a denial of service (crash) via crafted syscalls, possibly related to MCA/INIT, a different vulnerability than CVE-2005-1761.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0137">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0137</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:33.420-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T11:42:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11039" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11039" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-293.html" xml:lang="en">RHSA-2005:293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-284.html" xml:lang="en">RHSA-2005:284</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11039" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11039" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Linux kernel 2.6 on Itanium (ia64) architectures allows local users to cause a denial of service via a "missing Itanium syscall table entry."</vuln:summary>
  </entry>
  <entry id="CVE-2005-0138">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.25"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.26"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5.25</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.26</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.27</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0138</vuln:cve-id>
    <vuln:published-datetime>2005-09-21T16:03:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:35.267-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-09-21T16:23:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/p-214.shtml" xml:lang="en">P-214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2005/0702" xml:lang="en">ADV-2005-0702</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/15619" xml:lang="en">15619</vuln:reference>
    </vuln:references>
    <vuln:summary>rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not correctly allow access to anonymous clients that connect from a system whose hostname can not be determined.  NOTE: while this issue occurs in a security mechanism, there is no apparent attacker role and probably does not satisfy the CVE definition of a vulnerability.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0139">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.25"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.26"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5.27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.5.25</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.26</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5.27</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0139</vuln:cve-id>
    <vuln:published-datetime>2005-09-21T16:03:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:35.347-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-09-21T16:26:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/p-214.shtml" xml:lang="en">P-214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2005/0702" xml:lang="en">ADV-2005-0702</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/15619" xml:lang="en">15619</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not sufficiently restrict access rights for read-mostly exports, which allows attackers to conduct unauthorized activities.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0140">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:peid:peid:0.92"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:peid:peid:0.92</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0140</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:25.573-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T11:46:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19042" xml:lang="en">database-ida-portable-executable-bo(19042)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=189&amp;type=vulnerabilities" xml:lang="en">20050124 DataRescue Interactive Disassembler Pro Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12355" xml:lang="en">12355</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13984" xml:lang="en">13984</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in PeID allows attackers to execute arbitrary code via a PE file with an Import Address Table containing a long import library name.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0141">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7:rc3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7:rc3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0141</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:34.013-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T12:03:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10756" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10756" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:100057" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100057" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19168" xml:lang="en">mozilla-firefox-file-upload(19168)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-335.html" xml:lang="en">RHSA-2005:335</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-323.html" xml:lang="en">RHSA-2005:323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=249332" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=249332</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/mfsa2005-01.html" xml:lang="en">http://www.mozilla.org/security/announce/mfsa2005-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12407" xml:lang="en">12407</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:100057" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:100057" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10756" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10756" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to load local files via links "with a custom getter and toString method" that are middle-clicked by the user to be opened in a new tab.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0142">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7:rc3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0142</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:35.580-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T12:08:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9543" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9543" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:100056" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100056" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/17832" xml:lang="en">mozilla-world-readable(17832)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-335.html" xml:lang="en">RHSA-2005:335</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=251297" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=251297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2006_04_25.html" xml:lang="en">SUSE-SA:2006:004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/mfsa2005-02.html" xml:lang="en">http://www.mozilla.org/security/announce/mfsa2005-02.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-384.html" xml:lang="en">RHSA-2005:384</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2006_04_25.html" xml:lang="en">SUSE-SA:2006:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19823" xml:lang="en">19823</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9543" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9543" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:100056" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:100056" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0143">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.35"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.48"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.2:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.2:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.4:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.5:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.5:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.6:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.6:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.8:alpha2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.2:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.8:alpha2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.2.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.4:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.3.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.10.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.48</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.2.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.4:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.4.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.5:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.6:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.4.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7:rc3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.35</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.4.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.6:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.5:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:0.9.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.2:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.4.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9:rc</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.5:alpha</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0143</vuln:cve-id>
    <vuln:published-datetime>2005-03-23T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:34.280-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T12:13:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11297" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11297" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:100055" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100055" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=257308" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=257308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19166" xml:lang="en">mozilla-ssl-spoofing(19166)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-335.html" xml:lang="en">RHSA-2005:335</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/mfsa2005-03.html" xml:lang="en">http://www.mozilla.org/security/announce/mfsa2005-03.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12407" xml:lang="en">12407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-384.html" xml:lang="en">RHSA-2005:384</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:100055" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:100055" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11297" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11297" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0144">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7:rc3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7:rc3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0144</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:34.403-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T12:20:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11016" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11016" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:100054" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100054" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19169" xml:lang="en">mozilla-ssl-view-source-spoofing(19169)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-335.html" xml:lang="en">RHSA-2005:335</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-323.html" xml:lang="en">RHSA-2005:323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=262689" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=262689</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/mfsa2005-04.html" xml:lang="en">http://www.mozilla.org/security/announce/mfsa2005-04.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12407" xml:lang="en">12407</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:100054" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:100054" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11016" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11016" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0145">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:0.10.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9:rc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0145</vuln:cve-id>
    <vuln:published-datetime>2005-01-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:35:02.290-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T12:29:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:100051" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100051" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=265176" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=265176</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19170" xml:lang="en">mozilla-script-click-event-bypass(19170)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/mfsa2005-07.html" xml:lang="en">http://www.mozilla.org/security/announce/mfsa2005-07.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12407" xml:lang="en">12407</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:100051" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:100051" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0146">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7:rc3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7:rc3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0146</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:34.623-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T12:21:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10362" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10362" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-335.html" xml:lang="en">RHSA-2005:335</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=265728" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=265728</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19171" xml:lang="en">mozilla-middle-click-information-disclosure(19171)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/mfsa2005-08.html" xml:lang="en">http://www.mozilla.org/security/announce/mfsa2005-08.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12407" xml:lang="en">12407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-384.html" xml:lang="en">RHSA-2005:384</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10362" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10362" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to obtain sensitive data from the clipboard via Javascript that generates a middle-click event on systems for which a middle-click performs a paste operation.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0147">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7:rc3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7:rc3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0147</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:34.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T12:22:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9578" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9578" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:100049" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100049" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19174" xml:lang="en">mozilla-407-proxy-obtain-information(19174)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-323.html" xml:lang="en">RHSA-2005:323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=267263" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=267263</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/mfsa2005-09.html" xml:lang="en">http://www.mozilla.org/security/announce/mfsa2005-09.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12407" xml:lang="en">12407</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9578" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9578" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:100049" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:100049" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0148">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0148</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:35:02.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T12:47:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:100048" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100048" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19173" xml:lang="en">thunderbird-javascript-handler-launch(19173)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=263546" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=263546</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/mfsa2005-10.html" xml:lang="en">http://www.mozilla.org/security/announce/mfsa2005-10.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12407" xml:lang="en">12407</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:100048" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:100048" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer and may expose the Thunderbird user to vulnerabilities in the version of Internet Explorer that is installed on the user's system.  NOTE: since the invocation between multiple products is a common practice, and the vulnerabilities inherent in multi-product interactions are not easily enumerable, this issue might be REJECTED in the future.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0149">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:mozilla:1.7:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7:rc3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:mozilla:1.7:rc2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0149</vuln:cve-id>
    <vuln:published-datetime>2005-02-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:36.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T12:36:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11407" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11407" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:100047" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100047" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=268107" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=268107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19172" xml:lang="en">mozilla-cookie-policy-bypass(19172)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-335.html" xml:lang="en">RHSA-2005:335</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-323.html" xml:lang="en">RHSA-2005:323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-094.html" xml:lang="en">RHSA-2005:094</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/mfsa2005-11.html" xml:lang="en">http://www.mozilla.org/security/announce/mfsa2005-11.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2006_04_25.html" xml:lang="en">SUSE-SA:2006:004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12407" xml:lang="en">12407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2006_04_25.html" xml:lang="en">SUSE-SA:2006:004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19823" xml:lang="en">19823</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11407" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11407" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:100047" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:100047" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers bypass the user's intended privacy and security policy by using cookies in e-mail messages.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0150">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:0.10.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9:rc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0150</vuln:cve-id>
    <vuln:published-datetime>2005-05-26T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:35:03.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T12:44:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:100046" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100046" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=265668" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=265668</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19187" xml:lang="en">mozilla-firefox-livefeed-xss(19187)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/mfsa2005-12.html" xml:lang="en">http://www.mozilla.org/security/announce/mfsa2005-12.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12407" xml:lang="en">12407</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:100046" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:100046" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0151">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:creative_suite:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:premiere:1.5::pro"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:creative_suite:1.0</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:8.0</vuln:product>
      <vuln:product>cpe:/a:adobe:premiere:1.5::pro</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0151</vuln:cve-id>
    <vuln:published-datetime>2005-06-13T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:27.607-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-13T09:49:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/techdocs/331688.html" xml:lang="en">http://www.adobe.com/support/techdocs/331688.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1014170" xml:lang="en">1014170</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1014169" xml:lang="en">1014169</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1014168" xml:lang="en">1014168</vuln:reference>
    </vuln:references>
    <vuln:summary>Unknown vulnerability in the installation of Adobe License Management Service, as used in Adobe Photoshop CS, Adobe Creative Suite 1.0, and Adobe Premiere Pro 1.5, allows attackers to gain administrator privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0152">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0152</vuln:cve-id>
    <vuln:published-datetime>2005-02-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:27.760-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T12:50:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/203214" xml:lang="en">VU#203214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-662" xml:lang="en">DSA-662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14096" xml:lang="en">14096</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."</vuln:summary>
  </entry>
  <entry id="CVE-2005-0155">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:larry_wall:perl:5.8.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0155</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:35.593-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T12:59:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10404" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10404" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19207" xml:lang="en">perl-perliodebug-file-overwrite(19207)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2005/0003/" xml:lang="en">2005-0003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12426" xml:lang="en">12426</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-105.html" xml:lang="en">RHSA-2005:105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-103.html" xml:lang="en">RHSA-2005:103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200502-13.xml" xml:lang="en">GLSA-200502-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110779723332339&amp;w=2" xml:lang="en">20050207 DMA[2005-0131a] - 'Setuid Perl PERLIO_DEBUG root owned file creation'</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110737149402683&amp;w=2" xml:lang="en">20050202 [USN-72-1] Perl vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitalmunition.com/DMA%5B2005-0131a%5D.txt" xml:lang="en">http://www.digitalmunition.com/DMA[2005-0131a].txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:031" xml:lang="en">MDKSA-2005:031</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2006-163.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2006-163.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/21646" xml:lang="en">21646</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14120" xml:lang="en">14120</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/updates/FEDORA--.shtml" xml:lang="en">FLSA-2006:152845</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=001056" xml:lang="en">CLSA-2006:1056</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10404" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10404" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to create arbitrary files via the PERLIO_DEBUG variable.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0156">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.3"/>
        <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.4.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::workstation_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:fedora_core:core_3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.0::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.1"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.2"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.0::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.1"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.2"/>
        <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:4.1::ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:4.1::ppc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:trustix:secure_linux:1.5</vuln:product>
      <vuln:product>cpe:/a:larry_wall:perl:5.8.4.5</vuln:product>
      <vuln:product>cpe:/o:trustix:secure_linux:2.2</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::advanced_server</vuln:product>
      <vuln:product>cpe:/a:larry_wall:perl:5.8.4</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:8.1</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:3.0</vuln:product>
      <vuln:product>cpe:/a:larry_wall:perl:5.8.4.2</vuln:product>
      <vuln:product>cpe:/a:larry_wall:perl:5.8.4.3</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.2</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::workstation_server</vuln:product>
      <vuln:product>cpe:/o:redhat:fedora_core:core_3.0</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.1</vuln:product>
      <vuln:product>cpe:/a:larry_wall:perl:5.8.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.3</vuln:product>
      <vuln:product>cpe:/o:trustix:secure_linux:2.0</vuln:product>
      <vuln:product>cpe:/a:larry_wall:perl:5.8.4.1</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:8.0</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.0::x86_64</vuln:product>
      <vuln:product>cpe:/o:trustix:secure_linux:2.1</vuln:product>
      <vuln:product>cpe:/a:larry_wall:perl:5.8.0</vuln:product>
      <vuln:product>cpe:/a:larry_wall:perl:5.8.1</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:8.0::i386</vuln:product>
      <vuln:product>cpe:/a:larry_wall:perl:5.8.4.4</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:3.0</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.0</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:8.2</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:4.1::ia64</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
      <vuln:product>cpe:/a:larry_wall:perl:5.8.4.2.3</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:4.1::ppc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0156</vuln:cve-id>
    <vuln:published-datetime>2005-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:35.717-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T13:02:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10803" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10803" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19208" xml:lang="en">perl-perliodebug-bo(19208)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2005/0003/" xml:lang="en">2005-0003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12426" xml:lang="en">12426</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-105.html" xml:lang="en">RHSA-2005:105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-103.html" xml:lang="en">RHSA-2005:103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200502-13.xml" xml:lang="en">GLSA-200502-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitalmunition.com/DMA%5B2005-0131b%5D.txt" xml:lang="en">http://www.digitalmunition.com/DMA[2005-0131b].txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110779721503111&amp;w=2" xml:lang="en">20050207 DMA[2005-0131b] - 'Setuid Perl PERLIO_DEBUG</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110737149402683&amp;w=2" xml:lang="en">20050202 [USN-72-1] Perl vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:031" xml:lang="en">MDKSA-2005:031</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14120" xml:lang="en">14120</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/updates/FEDORA--.shtml" xml:lang="en">FLSA-2006:152845</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=001056" xml:lang="en">CLSA-2006:1056</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10803" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10803" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0157">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:smartlist:smartlist:3.15"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:smartlist:smartlist:3.15</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0157</vuln:cve-id>
    <vuln:published-datetime>2005-05-03T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:35:03.460-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-05-12T15:53:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-720" xml:lang="en">DSA-720</vuln:reference>
    </vuln:references>
    <vuln:summary>The confirm add-on in SmartList 3.15 and earlier allows attackers to subscribe arbitrary e-mail addresses by using a valid cookie that specifies an address other than the address for which the cookie was assigned.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0158">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.1.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.1.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.3.0_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.3.16"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:bidwatcher:bidwatcher:1.3.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.3.8</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.3.2</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.3.1</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.1.9.2</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.1.2</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.3.10</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.3.9</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.3.14</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.3.6</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.3.12</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.3.11</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.3.3</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.3.13</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.1.9.1</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.0.5</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.2.0</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.3.4</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.3.0_beta</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.3.16</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.1.7</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.1.8</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.3.15</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.1.9</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.3.7</vuln:product>
      <vuln:product>cpe:/a:bidwatcher:bidwatcher:1.3.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0158</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:28.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T13:29:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200503-06.xml" xml:lang="en">GLSA-200503-06</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-687" xml:lang="en">DSA-687</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in bidwatcher before 1.3.17 allows remote malicious web servers from eBay, or a spoofed eBay server, to cause a denial of service and possibly execute arbitrary code via certain responses.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0159">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:debian:toolchain-source:3.0.3-1"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:toolchain-source:3.0.3-2"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:toolchain-source:3.0.3-3"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:toolchain-source:3.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::arm"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::hppa"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ia-32"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ia-64"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::m68k"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::mips"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::mipsel"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::s-390"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::sparc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::hppa</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::mips</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ia-32</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::m68k</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::s-390</vuln:product>
      <vuln:product>cpe:/a:debian:toolchain-source:3.0.3-1</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::alpha</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::arm</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ia-64</vuln:product>
      <vuln:product>cpe:/a:debian:toolchain-source:3.0.3-2</vuln:product>
      <vuln:product>cpe:/a:debian:toolchain-source:3.0.3-3</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::mipsel</vuln:product>
      <vuln:product>cpe:/a:debian:toolchain-source:3.0.4</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::sparc</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ppc</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0159</vuln:cve-id>
    <vuln:published-datetime>2005-04-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:28.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12540" xml:lang="en">12540</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-679" xml:lang="en">DSA-679</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19317" xml:lang="en">toolchain-source-symlink(19317)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14277" xml:lang="en">14277</vuln:reference>
    </vuln:references>
    <vuln:summary>The tpkg-* scripts in the toolchain-source 3.0.4 package on Debian GNU/Linux 3.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0160">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:e-merge:unace:1.2b"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:e-merge:unace:1.2b</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0160</vuln:cve-id>
    <vuln:published-datetime>2005-02-22T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:28.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T13:08:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/215006" xml:lang="en">VU#215006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2005_16_sr.html" xml:lang="en">SUSE-SR:2005:016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14359" xml:lang="en">14359</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031908.html" xml:lang="en">20050222 unace-1.2b multiple buffer overflows and directory traversal bugs</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12630" xml:lang="en">12630</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in unace 1.2b allow attackers to execute arbitrary code via (1) 2 overflows in ACE archives, (2) a long command line argument, or (3) certain "Ready for next volume" messages.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0161">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:e-merge:unace:1.2b"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:e-merge:unace:1.2b</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0161</vuln:cve-id>
    <vuln:published-datetime>2005-02-22T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:29.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T13:10:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2005_16_sr.html" xml:lang="en">SUSE-SR:2005:016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14359" xml:lang="en">14359</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031908.html" xml:lang="en">20050222 unace-1.2b multiple buffer overflows and directory traversal bugs</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12628" xml:lang="en">12628</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0162">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openswan:openswan:2.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:openswan:openswan:1.0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openswan:openswan:2.3.0</vuln:product>
      <vuln:product>cpe:/a:openswan:openswan:1.0.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0162</vuln:cve-id>
    <vuln:published-datetime>2005-01-26T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:29.260-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T13:21:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19078" xml:lang="en">openswan-xauth-pam-bo(19078)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openswan.org/support/vuln/IDEF0785/" xml:lang="en">http://www.openswan.org/support/vuln/IDEF0785/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=190&amp;type=vulnerabilities" xml:lang="en">20050126 Openswan XAUTH/PAM Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12377" xml:lang="en">12377</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2005-January/msg00103.html" xml:lang="en">FEDORA-2005-082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/13195" xml:lang="en">13195</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013014" xml:lang="en">1013014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14062" xml:lang="en">14062</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14038" xml:lang="en">14038</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH and PAM enabled, allows remote authenticated attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0173">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.0.patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.0.patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.0.pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.0.release"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1.patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1.patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1.pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1.pre3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1.pre4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1.release"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.2.devel3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.2.devel4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.2.pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.2.pre2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.2.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.2.stable2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.2.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.2.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.2.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3.devel2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3.devel3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3.stable2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4.stable2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4.stable6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4.stable7"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squid:squid:2.1.patch2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.2.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.1.release</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.2.stable1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4.stable2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3.stable2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.2.stable2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.2.pre2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4.stable7</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3.devel3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.1.pre4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.0.patch2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.2.devel4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.0.release</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.2.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.1.pre3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.0.patch1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.1.patch1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.2.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.2.pre1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4.stable6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.0.pre1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.1.pre1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.2.devel3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3.devel2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4.stable1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3.stable1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0173</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:36.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T14:31:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10251" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10251" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/924198" xml:lang="en">VU#924198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-ldap_spaces.patch" xml:lang="en">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-ldap_spaces.patch</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-ldap_spaces" xml:lang="en">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-ldap_spaces</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-061.html" xml:lang="en">RHSA-2005:061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-060.html" xml:lang="en">RHSA-2005:060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2005_06_squid.html" xml:lang="en">SUSE-SA:2005:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-667" xml:lang="en">DSA-667</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2" xml:lang="en">20050207 [USN-77-1] Squid vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923" xml:lang="en">CLA-2005:923</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/bugs/show_bug.cgi?id=1187" xml:lang="en">http://www.squid-cache.org/bugs/show_bug.cgi?id=1187</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12431" xml:lang="en">12431</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034" xml:lang="en">MDKSA-2005:034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/updates/FEDORA--.shtml" xml:lang="en">FLSA-2006:152809</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10251" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10251" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0174">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable7"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_stable9</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0174</vuln:cve-id>
    <vuln:published-datetime>2005-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:36.513-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T13:30:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10656" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10656" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/768702" xml:lang="en">VU#768702</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-061.html" xml:lang="en">RHSA-2005:061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-060.html" xml:lang="en">RHSA-2005:060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-header_parsing" xml:lang="en">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-header_parsing</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html" xml:lang="en">FEDORA-2005-373</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2005_06_squid.html" xml:lang="en">SUSE-SA:2005:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2" xml:lang="en">20050207 [USN-77-1] Squid vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931" xml:lang="en">CLA-2005:931</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12412" xml:lang="en">12412</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034" xml:lang="en">MDKSA-2005:034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/updates/FEDORA--.shtml" xml:lang="en">FLSA-2006:152809</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10656" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10656" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0175">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable7"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_.stable6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5_stable9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_stable9</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5_stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0175</vuln:cve-id>
    <vuln:published-datetime>2005-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:36.637-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T13:42:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11605" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11605" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/625878" xml:lang="en">VU#625878</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-061.html" xml:lang="en">RHSA-2005:061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-060.html" xml:lang="en">RHSA-2005:060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2005_06_squid.html" xml:lang="en">SUSE-SA:2005:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-667" xml:lang="en">DSA-667</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2" xml:lang="en">20050207 [USN-77-1] Squid vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931" xml:lang="en">CLA-2005:931</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-response_splitting" xml:lang="en">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-response_splitting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/Advisories/SQUID-2005_5.txt" xml:lang="en">http://www.squid-cache.org/Advisories/SQUID-2005_5.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html" xml:lang="en">FEDORA-2005-373</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12433" xml:lang="en">12433</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034" xml:lang="en">MDKSA-2005:034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/updates/FEDORA--.shtml" xml:lang="en">FLSA-2006:152809</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11605" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11605" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0176">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:2.6.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:2.6.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0176</vuln:cve-id>
    <vuln:published-datetime>2005-02-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:36.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T13:52:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:8778" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8778" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1225" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1225" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-092.html" xml:lang="en">RHSA-2005:092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846102231365&amp;w=2" xml:lang="en">20050215 [USN-82-1] Linux kernel vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" xml:lang="en">CLA-2005:930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12598" xml:lang="en">12598</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-472.html" xml:lang="en">RHSA-2005:472</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19607" xml:lang="en">19607</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U" xml:lang="en">20060402-01-U</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:8778" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:8778" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1225" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1225" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0177">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0177</vuln:cve-id>
    <vuln:published-datetime>2005-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:36.903-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T13:58:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10298" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10298" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-092.html" xml:lang="en">RHSA-2005:092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://linux.bkbits.net:8080/linux-2.6/cset@41e2bfbeOiXFga62XrBhzm7Kv9QDmQ" xml:lang="en">http://linux.bkbits.net:8080/linux-2.6/cset@41e2bfbeOiXFga62XrBhzm7Kv9QDmQ</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" xml:lang="en">CLA-2005:930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12598" xml:lang="en">12598</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846102231365&amp;w=2" xml:lang="en">20050215 [USN-82-1] Linux kernel vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10298" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10298" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>nls_ascii.c in Linux before 2.6.8.1 uses an incorrect table size, which allows attackers to cause a denial of service (kernel crash) via a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0178">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:netkit:linux_netkit:0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:netkit:linux_netkit:0.17.17"/>
        <cpe-lang:fact-ref name="cpe:/a:vserver:linux-vserver:1.20"/>
        <cpe-lang:fact-ref name="cpe:/a:vserver:linux-vserver:1.21"/>
        <cpe-lang:fact-ref name="cpe:/a:vserver:linux-vserver:1.22"/>
        <cpe-lang:fact-ref name="cpe:/a:vserver:linux-vserver:1.23"/>
        <cpe-lang:fact-ref name="cpe:/a:vserver:linux-vserver:1.24"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.31"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.32"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.33"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.34"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.35"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.37"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.38"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.39"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.1.89"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.15:pre16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.15_pre20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.16:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.27:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.3.99"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.3.99:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.3.99:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.3.99:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.3.99:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.3.99:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.3.99:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.3.99:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22:pre10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23:pre9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23_ow2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24_ow1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.29:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.29:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.30:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.30:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.31:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.31"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.32"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.33"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.34"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.35"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.37"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.38"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.39"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.40"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.41"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.42"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.43"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.44"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.45"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.46"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.47"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.48"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.49"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.50"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.51"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.52"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.53"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.54"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.55"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.56"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.57"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.58"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.59"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.60"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.61"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.62"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.63"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.65"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.66"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.67"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.68"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.69"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6_test9_cvs"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.42</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.31</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.3.99:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.35</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.3.99:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.66</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.58</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.33</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.3.99</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.56</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.3.99:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.29:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.65</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23_ow2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.57</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.1.89</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.63</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.62</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.49</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.46</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.3.99:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.35</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.30:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.60</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.44</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.59</vuln:product>
      <vuln:product>cpe:/a:netkit:linux_netkit:0.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.3.99:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.55</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.3.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.41</vuln:product>
      <vuln:product>cpe:/a:vserver:linux-vserver:1.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.15:pre16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.34</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.61</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.37</vuln:product>
      <vuln:product>cpe:/a:netkit:linux_netkit:0.17.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.53</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.43</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.51</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.54</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.24_ow1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23:pre9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.13</vuln:product>
      <vuln:product>cpe:/a:vserver:linux-vserver:1.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.69</vuln:product>
      <vuln:product>cpe:/a:vserver:linux-vserver:1.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.40</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.30:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.16:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.38</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.39</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.47</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre7</vuln:product>
      <vuln:product>cpe:/a:vserver:linux-vserver:1.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.6:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.3.99:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.39</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.31:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.67</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.3.99:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.7:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.22:pre10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.31</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.9.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.32</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.29:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.37</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.45</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18::x86</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.38</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6_test9_cvs</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.48</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.15_pre20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.33</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.50</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.27:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.34</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre6</vuln:product>
      <vuln:product>cpe:/a:vserver:linux-vserver:1.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.52</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.68</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.32</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.5.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0178</vuln:cve-id>
    <vuln:published-datetime>2005-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:37.030-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T14:09:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10647" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10647" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-092.html" xml:lang="en">RHSA-2005:092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://linux.bkbits.net:8080/linux-2.6/cset@41ddda70CWJb5nNL71T4MOlG2sMG8A" xml:lang="en">http://linux.bkbits.net:8080/linux-2.6/cset@41ddda70CWJb5nNL71T4MOlG2sMG8A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12598" xml:lang="en">12598</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846102231365&amp;w=2" xml:lang="en">20050215 [USN-82-1] Linux kernel vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" xml:lang="en">CLA-2005:930</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10647" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10647" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Race condition in the setsid function in Linux before 2.6.8.1 allows local users to cause a denial of service (crash) and possibly access portions of kernel memory, related to TTY changes, locking, and semaphores.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0179">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22:pre10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23:pre9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23_ow2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24_ow1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.29:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.29:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.30:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.30:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.31:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:2.6.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6_test9_cvs"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.24_ow1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23:pre9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:2.6.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.29:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23_ow2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.30:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.6:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.31:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.30:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.7:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.22:pre10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.29:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18::x86</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6_test9_cvs</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0179</vuln:cve-id>
    <vuln:published-datetime>2005-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:37.330-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T14:20:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9890" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9890" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-092.html" xml:lang="en">RHSA-2005:092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2005/1878" xml:lang="en">ADV-2005-1878</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030660.html" xml:lang="en">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" xml:lang="en">CLA-2005:930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-663.html" xml:lang="en">RHSA-2005:663</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/17002" xml:lang="en">17002</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9890" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9890" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0180">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:2.6.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6_test9_cvs"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6_test9_cvs</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.7:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:2.6.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.6:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0180</vuln:cve-id>
    <vuln:published-datetime>2005-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:37.423-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>3.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T14:29:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10667" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10667" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-092.html" xml:lang="en">RHSA-2005:092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" xml:lang="en">MDKSA-2005:219</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030660.html" xml:lang="en">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" xml:lang="en">CLA-2005:930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12198" xml:lang="en">12198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/386374" xml:lang="en">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" xml:lang="en">MDKSA-2005:219</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:218" xml:lang="en">MDKSA-2005:218</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/17826" xml:lang="en">17826</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10667" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10667" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple integer signedness errors in the sg_scsi_ioctl function in scsi_ioctl.c for Linux 2.6.x allow local users to read or modify kernel memory via negative integers in arguments to the scsi ioctl, which bypass a maximum length check before calling the copy_from_user and copy_to_user functions.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0182">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mod_dosevasive:mod_dosevasive:1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mod_dosevasive:mod_dosevasive:1.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mod_dosevasive:mod_dosevasive:1.8</vuln:product>
      <vuln:product>cpe:/a:mod_dosevasive:mod_dosevasive:1.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0182</vuln:cve-id>
    <vuln:published-datetime>2005-01-06T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:31.963-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T14:32:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18765" xml:lang="en">moddosevasive-symlink(18765)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12181" xml:lang="en">12181</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-01-01" xml:lang="en">http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-01-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547469530582&amp;w=2" xml:lang="en">20050111 Mod_dosevasive symlink and race vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13725" xml:lang="en">13725</vuln:reference>
    </vuln:references>
    <vuln:summary>The mod_dosevasive module 1.9 and earlier for Apache creates temporary files with predictable filenames, which could allow remote attackers to overwrite arbitrary files via a symlink attack.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0183">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:vacation_plugin:0.15"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squirrelmail:vacation_plugin:0.15</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0183</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:32.120-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T14:34:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18855" xml:lang="en">vacation-ftpfile-command-execution(18855)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-03" xml:lang="en">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549426300953&amp;w=2" xml:lang="en">20050111 Squirrelmail vacation v0.15 local root exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squirrelmail.org/plugin_view.php?id=51" xml:lang="en">http://www.squirrelmail.org/plugin_view.php?id=51</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12222" xml:lang="en">12222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012866" xml:lang="en">1012866</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13791" xml:lang="en">13791</vuln:reference>
    </vuln:references>
    <vuln:summary>ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to execute arbitrary commands via shell metacharacters in a command line argument.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0184">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:vacation_plugin:0.15"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:cve-id>CVE-2005-0184</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:32.293-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T14:34:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18856" xml:lang="en">vacation-ftpfile-directory-traversal(18856)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-03" xml:lang="en">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549426300953&amp;w=2" xml:lang="en">20050111 Squirrelmail vacation v0.15 local root exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squirrelmail.org/plugin_view.php?id=51" xml:lang="en">http://www.squirrelmail.org/plugin_view.php?id=51</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12222" xml:lang="en">12222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012866" xml:lang="en">1012866</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13791" xml:lang="en">13791</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to read arbitrary files via a .. (dot dot) in a get request.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0185">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mnet_soft_factory:nodemanager_professional:2.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mnet_soft_factory:nodemanager_professional:2.00</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0185</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:32.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T14:39:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18937" xml:lang="en">nodemanager-linkdown-bo(18937)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.security.org.sg/vuln/nodemanager200.html" xml:lang="en">http://www.security.org.sg/vuln/nodemanager200.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13881/" xml:lang="en">13881</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599796118583&amp;w=2" xml:lang="en">20050117 [SIG^2 G-TEC] NodeManager Professional V2.00 Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12283" xml:lang="en">12283</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012915" xml:lang="en">1012915</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in NodeManager Professional 2.00 allows remote attackers to execute arbitrary commands via a LinkDown-Trap packet that contains a long OCTET-STRING in the Trap variable-bindings field.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0186">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1yd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3t"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:12.1yd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0186</vuln:cve-id>
    <vuln:published-datetime>2005-01-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-03-04T00:29:26.593-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T14:42:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4849" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4849" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18956" xml:lang="en">cisco-ios-sccp-dos(18956)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20050119-itscme.shtml" xml:lang="en">20050119 Vulnerability in Cisco IOS Embedded Call Processing Solutions</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012945" xml:lang="en">1012945</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13913" xml:lang="en">13913</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4849" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4849" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Cisco IOS 12.1YD, 12.2T, 12.3 and 12.3T, when configured for the IOS Telephony Service (ITS), CallManager Express (CME) or Survivable Remote Site Telephony (SRST), allows remote attackers to cause a denial of service (device reboot) via a malformed packet to the SCCP port.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0187">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:athoc:athoc_toolbar"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:athoc:athoc_toolbar</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0187</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:32.777-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T14:43:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/17627" xml:lang="en">athoc-toolbar-bo(17627)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11341" xml:lang="en">11341</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ngssoftware.com/advisories/athoc-01full.txt" xml:lang="en">http://www.ngssoftware.com/advisories/athoc-01full.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616363415176&amp;w=2" xml:lang="en">20050119 Multiple vulnerabilities in the AtHoc Toolbar (#NISR19012005c)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109710974324742&amp;w=2" xml:lang="en">20041006 Patch available for high risk flaws in the AtHoc Toolbar</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the SetSkin function in AtHoc toolbar allows remote attackers to execute arbitrary code via a long skin name.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0188">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:athoc:athoc_toolbar"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:athoc:athoc_toolbar</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0188</vuln:cve-id>
    <vuln:published-datetime>2004-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:32.933-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T14:57:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/17628" xml:lang="en">athoc-toolbar-format-string(17628)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11341" xml:lang="en">11341</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ngssoftware.com/advisories/athoc-01full.txt" xml:lang="en">http://www.ngssoftware.com/advisories/athoc-01full.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616363415176&amp;w=2" xml:lang="en">20050119 Multiple vulnerabilities in the AtHoc Toolbar (#NISR19012005c)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109710974324742&amp;w=2" xml:lang="en">20041006 Patch available for high risk flaws in the AtHoc Toolbar</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in the SetBaseURL function in AtHoc toolbar allows remote attackers to execute arbitrary code via format string specifiers in an invalid URL that is recorded in the debug log.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0189">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0:::english"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0:::japanese"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0::german"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0_6.0.12.690"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5_6.0.12.1016_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5_6.0.12.1040"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:realnetworks:realone_player:1.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.0::german</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:2.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.5</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.5_6.0.12.1040</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.5_6.0.12.1016_beta</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.0_beta</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.0:::english</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.0_6.0.12.690</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.0:::japanese</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0189</vuln:cve-id>
    <vuln:published-datetime>2004-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:38.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T15:10:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/698390" xml:lang="en">VU#698390</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12311" xml:lang="en">12311</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://service.real.com/help/faq/security/040928_player/EN/" xml:lang="en">http://service.real.com/help/faq/security/040928_player/EN/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616636318261&amp;w=2" xml:lang="en">20050119 RealPlayer 'ShowPreferences' Buffer Overflow Vulnerability (#NISR19012005e)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/ntbugtraq/2005-q1/0046.html" xml:lang="en">20050119 RealPlayer 'ShowPreferences' Buffer Overflow Vulnerability (#NISR19012005e)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2" xml:lang="en">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the HandleAction function in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to execute arbitrary code via a long ShowPreferences argument.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0190">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0:::english"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0:::japanese"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0::german"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0_6.0.12.690"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5_6.0.12.1016_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5_6.0.12.1040"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:realnetworks:realone_player:1.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.0::german</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:2.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.5</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.5_6.0.12.1040</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.5_6.0.12.1016_beta</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.0_beta</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.0:::english</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.0_6.0.12.690</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.0:::japanese</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0190</vuln:cve-id>
    <vuln:published-datetime>2004-09-29T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:38.220-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T15:35:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/17551" xml:lang="en">realplayer-media-file-deletion(17551)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11308" xml:lang="en">11308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ngssoftware.com/advisories/real-02full.txt" xml:lang="en">http://www.ngssoftware.com/advisories/real-02full.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://service.real.com/help/faq/security/040928_player/EN/" xml:lang="en">http://service.real.com/help/faq/security/040928_player/EN/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/12672/" xml:lang="en">12672</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616160228843&amp;w=2" xml:lang="en">20050119 RealPlayer Arbitrary File Deletion Vulnerability (#NISR19012005f)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2" xml:lang="en">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to delete arbitrary files via a Real Metadata Packages (RMP) file with a FILENAME tag containing .. (dot dot) sequences in a filename that ends with a ? (question mark) and an allowed file extension (e.g. .mp3), which bypasses the check for the file extension.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0191">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0:::english"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0:::japanese"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0::german"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0_6.0.12.690"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5_6.0.12.1016_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5_6.0.12.1040"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:realnetworks:realone_player:1.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.0::german</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:2.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.5</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.5_6.0.12.1040</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.5_6.0.12.1016_beta</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.0_beta</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.0:::english</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.0_6.0.12.690</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.0:::japanese</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0191</vuln:cve-id>
    <vuln:published-datetime>2005-01-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:38.297-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T15:46:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18982" xml:lang="en">realplayer-long-filename-offbyone-bo(18982)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ngssoftware.com/advisories/real-03full.txt" xml:lang="en">http://www.ngssoftware.com/advisories/real-03full.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://service.real.com/help/faq/security/040928_player/EN/" xml:lang="en">http://service.real.com/help/faq/security/040928_player/EN/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2" xml:lang="en">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2" xml:lang="en">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</vuln:reference>
    </vuln:references>
    <vuln:summary>Off-by-one buffer overflow in the processing of tags in Real Metadata Package (RMP) files in RealPlayer 10.5 (6.0.12.1040) and earlier could allow remote attackers to execute arbitrary code via a long tag.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0192">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realone_player:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0:::english"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0:::japanese"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0::german"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0_6.0.12.690"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.0_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5_6.0.12.1016_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:10.5_6.0.12.1040"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:realnetworks:realone_player:1.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.0::german</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realone_player:2.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.5</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.5_6.0.12.1040</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.5_6.0.12.1016_beta</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.0_beta</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.0:::english</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.0_6.0.12.690</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:10.0:::japanese</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0192</vuln:cve-id>
    <vuln:published-datetime>2004-10-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:19:38.393-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T15:48:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/18984" xml:lang="en">realplayer-rjs-filenane-directory-traversal(18984)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ngssoftware.com/advisories/real-03full.txt" xml:lang="en">http://www.ngssoftware.com/advisories/real-03full.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://service.real.com/help/faq/security/040928_player/EN/" xml:lang="en">http://service.real.com/help/faq/security/040928_player/EN/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2" xml:lang="en">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2" xml:lang="en">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in the parsing of Skin file names in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an RJS filename.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0193">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:isync:mrouter:1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:isync:mrouter:1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0193</vuln:cve-id>
    <vuln:published-datetime>2005-01-22T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:33.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T15:52:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19011" xml:lang="en">isync-mrouter-bo(19011)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110642400018425&amp;w=2" xml:lang="en">20050122 Mac OS X 10.3 iSync Privilege Escalation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2005/Apr/msg00001.html" xml:lang="en">APPLE-SA-2005-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12334" xml:lang="en">12334</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1012974" xml:lang="en">1012974</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13965" xml:lang="en">13965</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0194">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.0.patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.0.patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.0.pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.0.release"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1.patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1.patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1.pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1.pre3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1.pre4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.1.release"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.2.devel3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.2.devel4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.2.pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.2.pre2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.2.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.2.stable2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.2.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.2.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.2.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3.devel2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3.devel3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3.stable2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.3.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4.stable2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4.stable6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.4.stable7"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.5.stable6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squid:squid:2.1.patch2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.2.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.1.release</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.2.stable1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4.stable2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3.stable2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.2.stable2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.2.pre2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4.stable7</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3.devel3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.1.pre4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.0.patch2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.2.devel4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.0.release</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.2.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.1.pre3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.0.patch1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.1.patch1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.2.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.2.pre1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4.stable6</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.0.pre1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.1.pre1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.2.devel3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.5.stable1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3.devel2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.4.stable1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.3.stable1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0194</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:33.963-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T23:48:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/260421" xml:lang="en">VU#260421</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-empty_acls.patch" xml:lang="en">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-empty_acls.patch</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-empty_acls" xml:lang="en">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-empty_acls</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-667" xml:lang="en">DSA-667</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110901183320453&amp;w=2" xml:lang="en">20050221 [USN-84-1] Squid vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923" xml:lang="en">CLA-2005:923</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/bugs/show_bug.cgi?id=1166" xml:lang="en">http://www.squid-cache.org/bugs/show_bug.cgi?id=1166</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/updates/FEDORA--.shtml" xml:lang="en">FLSA-2006:152809</vuln:reference>
    </vuln:references>
    <vuln:summary>Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0195">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sz"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2b"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2bc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2bx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2bz"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2cx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2cz"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2ew"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2ewa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2jk"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2mc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2se"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2su"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sv"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sw"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sxa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sxb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sxd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sy"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sz"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yt"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yu"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yv"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yz"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2ze"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zh"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zi"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zj"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zn"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zo"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zp"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3b"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3bc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3bw"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3j"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3ja"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xh"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xi"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xk"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xm"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xn"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xq"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xr"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xs"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xt"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xu"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xw"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xy"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xz"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3ya"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3ye"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yh"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:12.2ewa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zj</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xz</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yt</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3ja</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sxa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sz</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sv</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2cz</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2bc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sxd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3b</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xs</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2mc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xt</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2bz</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xq</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xn</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sz</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yz</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3j</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xy</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3bw</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zi</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zp</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zn</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2su</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3ye</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2bx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2se</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2b</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yv</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2ze</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xm</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yu</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xu</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xi</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xw</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xr</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sxb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2ew</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sw</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3bc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zo</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3ya</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sy</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2jk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2cx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2t</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0195</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-03-04T00:29:27.517-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T17:32:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5813" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5813" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA05-026A.html" xml:lang="en">TA05-026A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/472582" xml:lang="en">VU#472582</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19072" xml:lang="en">cisco-ios-ipv6-dos(19072)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20050126-ipv6.shtml" xml:lang="en">20050126 Multiple Crafted IPv6 Packets Cause Reload</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5813" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5813" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Cisco IOS 12.0S through 12.3YH allows remote attackers to cause a denial of service (device restart) via a crafted IPv6 packet.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0196">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0da"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0db"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0dc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sp"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0st"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sy"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0sz"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0w5"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0wc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0wt"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0wx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xh"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xi"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xj"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xk"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xm"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xn"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xp"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xq"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xr"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xs"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xt"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xu"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0xv"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1aa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1ax"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1ay"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1az"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1da"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1db"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1dc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1e"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1ea"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1ec"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1eo"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1ev"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1ew"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1ex"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1ey"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xh"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xi"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xj"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xm"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xp"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xq"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xr"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xt"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xu"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1xv"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1ya"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1yb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1yf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1yh"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1yi"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1yj"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2b"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2bc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2bw"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2bx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2by"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2bz"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2cz"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2da"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2dd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2dx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2ew"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2jk"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2mb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2mc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2mx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2se"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2su"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sw"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sxa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sxb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sxd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sy"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sz"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2x"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xh"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xi"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xj"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xk"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xm"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xn"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xq"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xs"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xt"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xu"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xw"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2xz"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2ya"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2ye"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yh"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yj"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yk"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2ym"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yn"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yo"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yp"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yq"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yr"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2ys"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yt"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yu"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yv"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yw"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yy"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2yz"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2za"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2ze"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zh"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zi"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zj"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zk"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zm"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zn"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zo"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2zp"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3b"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3bw"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xh"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xi"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xj"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xk"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xl"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xn"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xq"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xr"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xs"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xu"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xv"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3ya"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3ye"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yh"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yj"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yl"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:12.1ew</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xv</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2cz</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sxd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xp</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2bw</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yz</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yr</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xj</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2bx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0db</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xi</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xv</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1ya</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1ay</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2se</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yu</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xt</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xi</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2by</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xj</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yy</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0dc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xn</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yn</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xj</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xu</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3ya</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2jk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1eo</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1yb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1ax</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zj</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1ev</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xt</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1yh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yw</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2x</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2bc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xs</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3bw</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2su</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xu</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xu</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sy</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sxb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1ey</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1aa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xs</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2dd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xq</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1yf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yj</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0da</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1ex</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zo</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xn</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1dc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xm</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yo</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sz</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sxa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xq</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3b</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xs</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0wt</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2mc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xt</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yq</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2bz</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sz</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zp</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zn</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0w5</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xm</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3ye</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xm</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yv</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xl</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2ze</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1ea</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2mb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2ye</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1da</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yp</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2mx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xq</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xr</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xi</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yt</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xr</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2za</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zm</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xp</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xw</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xi</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xq</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2ya</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xn</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2da</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0wx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2ym</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zi</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1xu</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0st</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xj</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1yj</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2ys</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2b</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yj</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1yi</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xr</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2ew</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sw</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1db</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1az</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0wc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1ec</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.1e</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0sp</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0xv</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2zc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xz</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sy</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2dx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2yk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2xl</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0196</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-03-04T00:29:27.717-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T17:50:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5652" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5652" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA05-026A.html" xml:lang="en">TA05-026A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/689326" xml:lang="en">VU#689326</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19074" xml:lang="en">cisco-ios-bgp-packetdos(19074)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20050126-bgp.shtml" xml:lang="en">20050126 Cisco IOS Misformed BGP Packet Causes Reload</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013013" xml:lang="en">1013013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14034" xml:lang="en">14034</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5652" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5652" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Cisco IOS 12.0 through 12.3YL, with BGP enabled and running the bgp log-neighbor-changes command, allows remote attackers to cause a denial of service (device reload) via a malformed BGP packet.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0197">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.1t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3t"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:12.1t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0197</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-03-04T00:29:27.843-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.1</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T17:56:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5662" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5662" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA05-026A.html" xml:lang="en">TA05-026A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/583638" xml:lang="en">VU#583638</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19071" xml:lang="en">cisco-ios-mpls-dos(19071)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20050126-les.shtml" xml:lang="en">20050126 Crafted Packet Causes Reload on Cisco Routers</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12369" xml:lang="en">12369</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013015" xml:lang="en">1013015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14031" xml:lang="en">14031</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5662" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5662" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Cisco IOS 12.1T, 12.2, 12.2T, 12.3 and 12.3T, with Multi Protocol Label Switching (MPLS) installed but disabled, allows remote attackers to cause a denial of service (device reload) via a crafted packet sent to the disabled interface.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0198">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:uw-imap"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:university_of_washington:uw-imap</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0198</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:38.733-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-03T21:08:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11306" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11306" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/CRDY-68QSL5" xml:lang="en">http://www.kb.cert.org/vuls/id/CRDY-68QSL5</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/702777" xml:lang="en">VU#702777</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-128.html" xml:lang="en">RHSA-2005:128</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200502-02.xml" xml:lang="en">GLSA-200502-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12391" xml:lang="en">12391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:026" xml:lang="en">MDKSA-2005:026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013037" xml:lang="en">1013037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14097" xml:lang="en">14097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14057" xml:lang="en">14057</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11306" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11306" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0199">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ngircd:ngircd:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ngircd:ngircd:0.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ngircd:ngircd:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ngircd:ngircd:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ngircd:ngircd:0.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ngircd:ngircd:0.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ngircd:ngircd:0.7.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ngircd:ngircd:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ngircd:ngircd:0.8.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ngircd:ngircd:0.6</vuln:product>
      <vuln:product>cpe:/a:ngircd:ngircd:0.7.6</vuln:product>
      <vuln:product>cpe:/a:ngircd:ngircd:0.7</vuln:product>
      <vuln:product>cpe:/a:ngircd:ngircd:0.7.1</vuln:product>
      <vuln:product>cpe:/a:ngircd:ngircd:0.8</vuln:product>
      <vuln:product>cpe:/a:ngircd:ngircd:0.7.7</vuln:product>
      <vuln:product>cpe:/a:ngircd:ngircd:0.6.1</vuln:product>
      <vuln:product>cpe:/a:ngircd:ngircd:0.7.5</vuln:product>
      <vuln:product>cpe:/a:ngircd:ngircd:0.8.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0199</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:45:35.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-06T08:42:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/19143" xml:lang="en">ngircd-listmakemask-bo(19143)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12397" xml:lang="en">12397</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-40.xml" xml:lang="en">GLSA-200501-40</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://arthur.ath.cx/pipermail/ngircd-ml/2005-January/000228.html" xml:lang="en">[ngIRCd-ML] 20050126 ngIRCd 0.8.2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.gentoo.org/show_bug.cgi?id=79705" xml:lang="en">http://bugs.gentoo.org/show_bug.cgi?id=79705</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013047" xml:lang="en">1013047</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14059" xml:lang="en">14059</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14056" xml:lang="en">14056</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MODE line that causes an incorrect length calculation, which leads to a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0200">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:tiki:tikiwiki_cms%2Fgroupware:1.6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tiki:tikiwiki_cms%2Fgroupware:1.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0200</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-24T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-06T08:44:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200501-41.xml" xml:lang="en">GLSA-200501-41</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://tikiwiki.org/art102" xml:lang="en">http://tikiwiki.org/art102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/13948" xml:lang="en">13948</vuln:reference>
    </vuln:references>
    <vuln:summary>TikiWiki before 1.8.5 does not properly validate files that have been uploaded to the temp directory, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2004-1386.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0201">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:d-bus:d-bus:0.22"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:d-bus:d-bus:0.22</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0201</vuln:cve-id>
    <vuln:published-datetime>2005-06-29T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:39.077-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-29T08:34:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10973" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10973" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-102.html" xml:lang="en">RHSA-2005:102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:105" xml:lang="en">MDKSA-2005:105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntulinux.org/support/documentation/usn/usn-144-1" xml:lang="en">USN-144-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>AUSCERT</vuln:source>
      <vuln:reference href="http://www.auscert.org.au/render.html?it=5156" xml:lang="en">ESB-2005.0435</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12435" xml:lang="en">12435</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013075" xml:lang="en">1013075</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/15844" xml:lang="en">15844</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/15833" xml:lang="en">15833</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/15638" xml:lang="en">15638</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14119" xml:lang="en">14119</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10973" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10973" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user's per-user session bus via that socket.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0202">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1b1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:mailman:2.1.1</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.1.3</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.1.5</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.1.4</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.1</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.1b1</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0202</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:39.217-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-06T08:57:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10657" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10657" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-137.html" xml:lang="en">RHSA-2005:137</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-136.html" xml:lang="en">RHSA-2005:136</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200502-11.xml" xml:lang="en">GLSA-200502-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110805795122386&amp;w=2" xml:lang="en">20050209 [USN-78-1] Mailman vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" xml:lang="en">APPLE-SA-2005-03-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-674" xml:lang="en">DSA-674</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031562.html" xml:lang="en">20050209 Administrivia: List Compromised due to Mailman Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2005_07_mailman.html" xml:lang="en">SUSE-SA:2005:007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:037" xml:lang="en">MDKSA-2005:037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1013145" xml:lang="en">1013145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/14211" xml:lang="en">14211</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10657" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10657" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary files via ".../....///" sequences, which are not properly cleansed by regular expressions that are intended to remove "../" and "./" sequences.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0203">
    <vuln:cve-id>CVE-2005-0203</vuln:cve-id>
    <vuln:published-datetime>2005-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:35:06.837-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate has been revoked by its Candidate Numbering Authority (CNA) because it was initially assigned to a problem that was not a security issue.  Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0204">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0204</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:39.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-06T09:09:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10320" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10320" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-092.html" xml:lang="en">RHSA-2005:092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2006/0006" xml:lang="en">2006-0006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12598" xml:lang="en">12598</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-293.html" xml:lang="en">RHSA-2005:293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18784" xml:lang="en">18784</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10320" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10320" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Linux kernel before 2.6.9, when running on the AMD64 and Intel EM64T architectures, allows local users to write to privileged IO ports via the OUTS instruction.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0205">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bernd_wuebben:kppp:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:kde:kde:3.1.5</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1.4</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1</vuln:product>
      <vuln:product>cpe:/o:bernd_wuebben:kppp:2.1.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0205</vuln:cve-id>
    <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:39.497-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2005-06-06T09:20:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9596" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9596" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-175.html" xml:lang="en">RHSA-2005:175</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kde.org/info/security/advisory-20050228-1.txt" xml:lang="en">http://www.kde.org/info/security/advisory-20050228-1.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/application/poi/display?id=208&amp;type=vulnerabilities" xml:lang="en">20050228 KPPP Privileged File Descriptor Leak Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-692" xml:lang="en">DSA-692</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONECTIVA</vuln:source>
      <vuln:reference href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000934" xml:lang="en">CLA-2005:934</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9596" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9596" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control over DNS name resolution by opening a number of file descriptors before executing kppp.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0206">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ascii:ptex:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:cstex:cstetex:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.0.4_8"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.19_rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.20"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.4_2"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.4_3"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.4_5"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_software_products:cups:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gpdf:0.110"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gpdf:0.112"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gpdf:0.131"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:koffice:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:koffice:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:koffice:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:koffice:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:koffice:1.3_beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:koffice:1.3_beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:koffice:1.3_beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:kpdf:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pdftohtml:pdftohtml:0.32a"/>
        <cpe-lang:fact-ref name="cpe:/a:pdftohtml:pdftohtml:0.32b"/>
        <cpe-lang:fact-ref name="cpe:/a:pdftohtml:pdftohtml:0.33"/>
        <cpe-lang:fact-ref name="cpe:/a:pdftohtml:pdftohtml:0.33a"/>
        <cpe-lang:fact-ref name="cpe:/a:pdftohtml:pdftohtml:0.34"/>
        <cpe-lang:fact-ref name="cpe:/a:pdftohtml:pdftohtml:0.35"/>
        <cpe-lang:fact-ref name="cpe:/a:pdftohtml:pdftohtml:0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:propack:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:tetex:tetex:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:tetex:tetex:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:tetex:tetex:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:tetex:tetex:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tetex:tetex:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.90"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.91"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.92"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:0.93"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:1.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:advanced_linux_environment:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::arm"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::hppa"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ia-32"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ia-64"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::m68k"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::mips"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::mipsel"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::s-390"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::advanced_servers"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:fedora_core:core_1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:fedora_core:core_2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:fedora_core:core_3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:9.0::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux_advanced_workstation:2.1::ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux_advanced_workstation:2.1::itanium_processor"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:4.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:6.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:6.3::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:6.3:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:6.4"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:6.4::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:6.4::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:6.4:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:7.0::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:7.0::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:7.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:7.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:7.1::spa"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:7.1::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:7.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:7.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:7.2::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:7.3"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:7.3::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:7.3::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:7.3::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.0::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.1"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8.2"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.0::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.1"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.1::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.2"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.2::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:4.1::ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:4.1::ppc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation_ia64</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.2</vuln:product>
      <vuln:product>cpe:/a:tetex:tetex:2.0.1</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:4.3</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.4_5</vuln:product>
      <vuln:product>cpe:/o:sgi:advanced_linux_environment:3.0</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::s-390</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:6.4</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.2.1</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.16</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.4_2</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:6.3::ppc</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:4.2</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::hppa</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:7.1::sparc</vuln:product>
      <vuln:product>cpe:/a:gnome:gpdf:0.112</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server_ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::workstation</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.2.2</vuln:product>
      <vuln:product>cpe:/a:kde:koffice:1.3.1</vuln:product>
      <vuln:product>cpe:/a:gnome:gpdf:0.131</vuln:product>
      <vuln:product>cpe:/a:kde:koffice:1.3_beta2</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:3.0</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:1.0a</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.2::x86_64</vuln:product>
      <vuln:product>cpe:/a:pdftohtml:pdftohtml:0.33a</vuln:product>
      <vuln:product>cpe:/a:pdftohtml:pdftohtml:0.36</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.7</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.20</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:7.0</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:8.2</vuln:product>
      <vuln:product>cpe:/o:redhat:fedora_core:core_1.0</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:5.1</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:4.1::ppc</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.93</vuln:product>
      <vuln:product>cpe:/a:tetex:tetex:2.0</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::advanced_servers</vuln:product>
      <vuln:product>cpe:/a:kde:koffice:1.3</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:8.1</vuln:product>
      <vuln:product>cpe:/a:tetex:tetex:2.0.2</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.2</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.14</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:1.0</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.3.1</vuln:product>
      <vuln:product>cpe:/o:redhat:fedora_core:core_3.0</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:2.0</vuln:product>
      <vuln:product>cpe:/a:gnome:gpdf:0.110</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.1</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:4.0</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ppc</vuln:product>
      <vuln:product>cpe:/a:cstex:cstetex:2.0.2</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.6</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.12</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0::x86_64</vuln:product>
      <vuln:product>cpe:/a:tetex:tetex:1.0.7</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ia-64</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:3.0</vuln:product>
      <vuln:product>cpe:/a:kde:kpdf:3.2</vuln:product>
      <vuln:product>cpe:/o:redhat:fedora_core:core_2.0</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.17</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.19</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:5.2</vuln:product>
      <vuln:product>cpe:/a:kde:koffice:1.3.3</vuln:product>
      <vuln:product>cpe:/a:ascii:ptex:3.1.4</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:7.1::spa</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:9.0::i386</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::mips</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:1.1</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:6.4::i386</vuln:product>
      <vuln:product>cpe:/a:sgi:propack:3.0</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::alpha</vuln:product>
      <vuln:product>cpe:/o:redhat:linux_advanced_workstation:2.1::itanium_processor</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:7.0::sparc</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.4_3</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:1.0</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::mipsel</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.3</vuln:product>
      <vuln:product>cpe:/a:kde:koffice:1.3_beta1</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:6.4::ppc</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:4.4</vuln:product>
      <vuln:product>cpe:/a:pdftohtml:pdftohtml:0.32b</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:5.3</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:linux_advanced_workstation:2.1::ia64</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:2.0</vuln:product>
      <vuln:product>cpe:/a:kde:koffice:1.3_beta3</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:2.1</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.18</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:8.0::i386</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:4.4.1</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.13</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server_ia64</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.0</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.4</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:4.1::ia64</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.10</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:7.3::ppc</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:6.0</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:7.0::i386</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.91</vuln:product>
      <vuln:product>cpe:/a:tetex:tetex:1.0.6</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.2.3</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:7.3</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ia-32</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:6.3</vuln:product>
      <vuln:product>cpe:/a:kde:koffice:1.3.2</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:7.1</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:6.4:alpha</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.19_rc5</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::arm</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:7.0::ppc</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.90</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:7.3::i386</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:7.0:alpha</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:6.1:alpha</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.1</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:7.2::i386</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.1.15</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:3.0</vuln:product>
      <vuln:product>cpe:/a:pdftohtml:pdftohtml:0.33</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.1::x86_64</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:5.0</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.0.4</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0</vuln:product>
      <vuln:product>cpe:/a:pdftohtml:pdftohtml:0.34</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:7.2</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:7.1::x86</vuln:product>
      <vuln:product>cpe:/a:easy_software_products:cups:1.0.4_8</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::m68k</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.0::x86_64</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:8.0</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:6.1</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:7.3::sparc</vuln:product>
      <vuln:product>cpe:/a:pdftohtml:pdftohtml:0.35</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:6.2</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:2.3</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:7.1:alpha</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::sparc</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:6.3:alpha</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:0.92</vuln:product>
      <vuln:product>cpe:/a:pdftohtml:pdftohtml:0.32a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2005-0206</vuln:cve-id>
    <vuln:published-datetime>2005-04-27T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:25:39.623-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11107" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11107" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/11501" xml:lang="en">11501</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-213.html" xml:lang="en">RHSA-2005:213</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/17818" xml:lang="en">xpdf-pdf-bo(17818)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-132.html" xml:lang="en">RHSA-2005:132</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-057.html" xml:lang="en">RHSA-2005:057</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-053.html" xml:lang="en">RHSA-2005:053</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2005-034.html" xml:lang="en">RHSA-2005:034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:056" xml:lang="en">MDKSA-2005:056</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:052" xml:lang="en">MDKSA-2005:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:044" xml:lang="en">MDKSA-2005:044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:043" xml:lang="en">MDKSA-2005:043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:042" xml:lang="en">MDKSA-2005:042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRAKE</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:041" xml:lang="en">MDKSA-2005:041</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11107" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11107" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.</vuln:summary>
  </entry>
  <entry id="CVE-2005-0207">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:conectiva:linux:10.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23:pre9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23_ow2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24_ow1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.29:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.29:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.31"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.32"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.33"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.34"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.35"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.37"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.38"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.39"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.40"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.41"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.42"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.43"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.44"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.45"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.46"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.47"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.48"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.49"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.50"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.51"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.52"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.53"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.54"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.55"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.56"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.57"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.58"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.59"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.60"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.61"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.62"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.63"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.65"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.66"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.67"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.68"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.69"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:2.6.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6_test9_cvs"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_l