<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:scap-core="http://scap.nist.gov/schema/scap-core/0.1" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" xmlns:patch="http://scap.nist.gov/schema/patch/0.1" xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" nvd_xml_version="2.0" pub_date="2013-05-22T05:57:14" xsi:schemaLocation="http://scap.nist.gov/schema/patch/0.1 http://nvd.nist.gov/schema/patch_0.1.xsd http://scap.nist.gov/schema/scap-core/0.1 http://nvd.nist.gov/schema/scap-core_0.1.xsd http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
  <entry id="CVE-2006-0001">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher:2003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:publisher:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:publisher:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:publisher:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0001</vuln:cve-id>
    <vuln:discovered-datetime>2005-08-03T00:00:00.000-04:00</vuln:discovered-datetime>
    <vuln:published-datetime>2006-09-12T19:07:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:09.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-09-13T12:32:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:590" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:590" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-255A.html" xml:lang="en">TA06-255A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/406236" xml:lang="en">VU#406236</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/19951" xml:lang="en">19951</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/445824/100/0/threaded" xml:lang="en">20060912 Computer Terrorism (UK) :: Incident Response Centre - Microsoft Publisher Font Parsing Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS06-054.mspx" xml:lang="en">MS06-054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.computerterrorism.com/research/ct12-09-2006-2.htm" xml:lang="en">http://www.computerterrorism.com/research/ct12-09-2006-2.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/21863" xml:lang="en">21863</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/28648" xml:lang="en">publisher-pub-code-execution(28648)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/3565" xml:lang="en">ADV-2006-3565</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/446630/100/100/threaded" xml:lang="en">SSRT061187</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/446630/100/100/threaded" xml:lang="en">HPSBST02134</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1016825" xml:lang="en">1016825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/1548" xml:lang="en">1548</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:590" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:590" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0002">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2002:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.0:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.0:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0002</vuln:cve-id>
    <vuln:published-datetime>2006-01-10T17:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-04-12T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T08:31:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:624" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:624" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1485" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1485" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1456" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1456" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1316" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1316" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1165" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1165" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1082" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1082" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-010A.html" xml:lang="en">TA06-010A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/252146" xml:lang="en">VU#252146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16197" xml:lang="en">16197</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421520/100/0/threaded" xml:lang="en">20060110 Microsoft Outlook Critical Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421518/100/0/threaded" xml:lang="en">20060110 Microsoft Exchange Critical Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-003.mspx" xml:lang="en">MS06-003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015461" xml:lang="en">1015461</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015460" xml:lang="en">1015460</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18368" xml:lang="en">18368</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/22878" xml:lang="en">win-tnef-overflow(22878)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0119" xml:lang="en">ADV-2006-0119</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/331" xml:lang="en">331</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/330" xml:lang="en">330</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1316" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1316" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1082" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1082" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1485" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1485" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1456" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1456" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1165" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1165" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:624" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:624" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0003">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.5:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.7:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.8:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.8:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.5:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.8</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.7:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.8:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.7</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.8:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0003</vuln:cve-id>
    <vuln:published-datetime>2006-04-11T20:02:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:09.187-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-04-12T14:06:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1778" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1778" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1742" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1742" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1511" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1511" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1323" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1323" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1204" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1204" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-101A.html" xml:lang="en">TA06-101A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/234812" xml:lang="en">VU#234812</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-014.mspx" xml:lang="en">MS06-014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/29915" xml:lang="en">ie-wscriptshell-command-execution(29915)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/25006" xml:lang="en">mdac-rdsdataspace-execute-code(25006)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/2452" xml:lang="en">ADV-2006-2452</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1319" xml:lang="en">ADV-2006-1319</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/data/vulnerabilities/exploits/0day_ie.pdf" xml:lang="en">http://www.securityfocus.com/data/vulnerabilities/exploits/0day_ie.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/20797" xml:lang="en">20797</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/17462" xml:lang="en">17462</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/487219/100/200/threaded" xml:lang="en">20080128 Re: Exploit in IE6,7</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/487216/100/200/threaded" xml:lang="en">20080128 Exploit in IE6,7</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/475490/100/100/threaded" xml:lang="en">20070731 Re: Exploit In Internet Explorer</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/475118/100/100/threaded" xml:lang="en">20070730 RE: Exploit In Internet Explorer</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/475108/100/100/threaded" xml:lang="en">20070730 Re: Exploit In Internet Explorer</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/475104/100/100/threaded" xml:lang="en">20070729 Exploit In Internet Explorer</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/24517" xml:lang="en">24517</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/2164" xml:lang="en">2164</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/2052" xml:lang="en">2052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/index-e.html" xml:lang="en">http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/index-e.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/01-e.html" xml:lang="en">http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/01-e.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015894" xml:lang="en">1015894</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20719" xml:lang="en">20719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19583" xml:lang="en">19583</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1323" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1323" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1778" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1778" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1204" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1204" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1742" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1742" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1511" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1511" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0004">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0004</vuln:cve-id>
    <vuln:published-datetime>2006-02-14T15:02:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:09.297-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-02-28T14:58:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1555" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1555" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/963628" xml:lang="en">VU#963628</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-010.mspx" xml:lang="en">MS06-010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0579" xml:lang="en">ADV-2006-0579</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24490" xml:lang="en">powerpoint-tiff-information-disclosure(24490)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16634" xml:lang="en">16634</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015632" xml:lang="en">1015632</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18865" xml:lang="en">18865</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1555" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1555" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF).</vuln:summary>
  </entry>
  <entry id="CVE-2006-0005">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:datacenter_server:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:datacenter_server:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:datacenter_server:sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:datacenter_server:sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:xp"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:xp:sp2:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:xp_tablet_pc"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:xp_tablet_pc:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:xp_tablet_pc:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:pro"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:pro"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:pro"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:pro"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_advanced_server:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_advanced_server:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_advanced_server:sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000_advanced_server:sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:datacenter_edition"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:datacenter_edition_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_edition"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_edition_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web_edition"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2000:none"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2000:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2000:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:datacenter_sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:enterprise_sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:standard_sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:web_edition_sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::pro"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:pro"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:pro"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003:web_edition_sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows-nt:datacenter_server:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_advanced_server:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:pro</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:pro</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_advanced_server:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:datacenter_edition</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_edition</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2000:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:pro</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003:standard_sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::pro</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows-nt:xp_tablet_pc:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003:enterprise_sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:pro</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2000:none</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:datacenter_edition_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003:datacenter_sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows-nt:xp:sp2:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows-nt:datacenter_server:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows-nt:xp</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows-nt:xp_tablet_pc:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows-nt:datacenter_server:sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2000:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows-nt:2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:pro</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_advanced_server:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_edition_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:pro</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows-nt:xp_tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows-nt:datacenter_server:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000_advanced_server:sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web_edition</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows-nt:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2000:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0005</vuln:cve-id>
    <vuln:published-datetime>2006-02-14T14:06:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:09.393-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-02-21T16:09:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1559" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1559" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-045A.html" xml:lang="en">TA06-045A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/692060" xml:lang="en">VU#692060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24493" xml:lang="en">win-mediaplayer-plugin-embed-bo(24493)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0575" xml:lang="en">ADV-2006-0575</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16644" xml:lang="en">16644</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-006.mspx" xml:lang="en">MS06-006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=393" xml:lang="en">20060214 Microsoft Windows Media Player Plugin Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015628" xml:lang="en">1015628</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18852" xml:lang="en">18852</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1559" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1559" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0006">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_player:10"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_player:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_player:9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4::fr"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:tablet_pc"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:windows_media_player:10</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_media_player:7.1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_media_player:9</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4::fr</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:tablet_pc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0006</vuln:cve-id>
    <vuln:published-datetime>2006-02-14T17:06:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-10-17T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-03-06T08:28:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1661" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1661" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1598" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1598" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1578" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1578" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1256" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1256" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-045A.html" xml:lang="en">TA06-045A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/291396" xml:lang="en">VU#291396</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16633" xml:lang="en">16633</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-005.mspx" xml:lang="en">MS06-005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.eeye.com/html/research/advisories/AD20060214.html" xml:lang="en">http://www.eeye.com/html/research/advisories/AD20060214.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015627" xml:lang="en">1015627</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18835" xml:lang="en">18835</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24488" xml:lang="en">win-media-player-bmp-bo(24488)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0574" xml:lang="en">ADV-2006-0574</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/425158/100/0/threaded" xml:lang="en">20060215 Windows Media Player BMP Heap Overflow (MS06-005)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/424983/100/0/threaded" xml:lang="en">20060214 [EEYEB-20051017] Windows Media Player BMP Heap Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/423" xml:lang="en">423</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1578" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1578" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1256" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1256" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1598" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1598" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1661" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1661" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0007">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0007</vuln:cve-id>
    <vuln:published-datetime>2006-07-11T17:05:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:09.547-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-07-12T10:33:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:21" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:21" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-192A.html" xml:lang="en">TA06-192A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/668564" xml:lang="en">VU#668564</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-039.mspx" xml:lang="en">MS06-039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/2757" xml:lang="en">ADV-2006-2757</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/18915" xml:lang="en">18915</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/439887/100/0/threaded" xml:lang="en">20060712 NSFOCUS SA2006-04 : Microsoft Office GIF Filter Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/27146" xml:lang="en">27146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1016470" xml:lang="en">1016470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/21013" xml:lang="en">21013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2006-q3/0005.html" xml:lang="en">20060712 NSFOCUS SA2006-04 : Microsoft Office GIF Filter Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:21" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:21" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in GIFIMP32.FLT, as used in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted GIF image that triggers memory corruption when it is parsed.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0008">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003::student_teacher"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:datacenter_64-bit:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003::student_teacher</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:datacenter_64-bit:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0008</vuln:cve-id>
    <vuln:published-datetime>2006-02-14T14:06:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-28T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-03-06T08:48:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:727" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:727" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1688" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1688" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1664" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1664" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1650" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1650" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1595" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1595" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/739844" xml:lang="en">VU#739844</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16643" xml:lang="en">16643</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-009.mspx" xml:lang="en">MS06-009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015631" xml:lang="en">1015631</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18859" xml:lang="en">18859</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24492" xml:lang="en">win-korean-ime-privilege-elevation(24492)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0578" xml:lang="en">ADV-2006-0578</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/425141/100/0/threaded" xml:lang="en">20060215 Security advisory: Windows IME Vulnerability (MS06-009)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ryanstyle.com/alert/my/5/ms06_009_eng.html" xml:lang="en">http://www.ryanstyle.com/alert/my/5/ms06_009_eng.html</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1650" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1650" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1688" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1688" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1664" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1664" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:727" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:727" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1595" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1595" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0009">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:v.x::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2001"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2006"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:works:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:v.x::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2001</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2006</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0009</vuln:cve-id>
    <vuln:published-datetime>2006-03-14T18:02:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:09.987-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-03-16T08:40:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:798" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:798" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1653" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1653" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1553" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1553" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1504" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1504" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-073A.html" xml:lang="en">TA06-073A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/682820" xml:lang="en">VU#682820</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/17000" xml:lang="en">17000</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/427671/100/0/threaded" xml:lang="en">20060314 SYMSA-2006-001: Buffer overflow in Microsoft Office 2000, Office XP (2002), and Office 2003 Routing Slip Metadata</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx" xml:lang="en">MS06-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015766" xml:lang="en">1015766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19138" xml:lang="en">19138</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/29009" xml:lang="en">powerpoint-presentation-code-execution(29009)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/25009" xml:lang="en">office-routing-slip-bo(25009)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/3678" xml:lang="en">ADV-2006-3678</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0950" xml:lang="en">ADV-2006-0950</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FMDROPPER%2EBH" xml:lang="en">http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FMDROPPER%2EBH</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-091810-5028-99" xml:lang="en">http://www.symantec.com/security_response/writeup.jsp?docid=2006-091810-5028-99</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.symantec.com/enterprise/research/SYMSA-2006-001.txt" xml:lang="en">http://www.symantec.com/enterprise/research/SYMSA-2006-001.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/20059" xml:lang="en">20059</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/446425/100/0/threaded" xml:lang="en">20060919 Microsoft PowerPoint 0-day Vulnerability FAQ - September written</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/446370/100/0/threaded" xml:lang="en">20060919 New PowerPoint 0-day Trojan in the wild</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/444051/100/200/threaded" xml:lang="en">20060822 Major updates in PowerPoint FAQ document - not a 0-day issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/443890/100/0/threaded" xml:lang="en">20060819 New PowerPoint 0-day and Trojan - FAQ document ready</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/432004/30/5340/threaded" xml:lang="en">20060422 PowerPoint Phishing Trojan</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/23903" xml:lang="en">23903</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.darkreading.com/document.asp?doc_id=101970" xml:lang="en">http://www.darkreading.com/document.asp?doc_id=101970</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1016886" xml:lang="en">1016886</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1016720" xml:lang="en">1016720</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19238" xml:lang="en">19238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049540.html" xml:lang="en">20060919 New PowerPoint 0-day Trojan in the wild</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isc.sans.org/diary.php?storyid=1618" xml:lang="en">http://isc.sans.org/diary.php?storyid=1618</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.securiteam.com/?p=559" xml:lang="en">http://blogs.securiteam.com/?p=559</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.securiteam.com/?p=557" xml:lang="en">http://blogs.securiteam.com/?p=557</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.securiteam.com/?author=28" xml:lang="en">http://blogs.securiteam.com/?author=28</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2006-08/0597.html" xml:lang="en">20060822 Major updates in PowerPoint FAQ document - not a 0-day issue</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1553" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1553" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1653" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1653" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1504" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1504" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:798" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:798" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E in attacks against PowerPoint.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0010">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:datacenter_64-bit:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp5"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp5:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server_alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:alpha</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:alpha</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server_alpha</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:alpha</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp5:alpha</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:alpha</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:alpha</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp5</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:alpha</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:datacenter_64-bit:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:alpha</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::alpha</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:professional</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0010</vuln:cve-id>
    <vuln:published-datetime>2006-01-10T17:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:10.080-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T08:36:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:714" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:714" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:698" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:698" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1491" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1491" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1462" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1462" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1185" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1185" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1126" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1126" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-010A.html" xml:lang="en">TA06-010A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/915930" xml:lang="en">VU#915930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16194" xml:lang="en">16194</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-002.mspx" xml:lang="en">MS06-002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18365" xml:lang="en">18365</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/23922" xml:lang="en">win-embedded-fonts-bo(23922)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=375525" xml:lang="en">http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=375525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0118" xml:lang="en">ADV-2006-0118</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421885/100/0/threaded" xml:lang="en">20060110 [EEYEB-2000801] - Windows Embedded Open Type (EOT) Font Heap Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/18829" xml:lang="en">18829</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EEYE</vuln:source>
      <vuln:reference href="http://www.eeye.com/html/Research/Advisories/EEYEB20050801.html" xml:lang="en">EEYEB20050801</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015459" xml:lang="en">1015459</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18391" xml:lang="en">18391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18311" xml:lang="en">18311</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:698" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:698" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1462" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1462" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1491" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1491" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1185" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1185" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1126" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1126" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:714" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:714" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0012">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:datacenter_64-bit:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:datacenter_64-bit:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:advanced_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0012</vuln:cve-id>
    <vuln:published-datetime>2006-04-11T20:02:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:10.187-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-04-12T14:04:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1764" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1764" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1743" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1743" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1679" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1679" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1448" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1448" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1191" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1191" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-101A.html" xml:lang="en">TA06-101A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/641460" xml:lang="en">VU#641460</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-015.mspx" xml:lang="en">MS06-015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19606" xml:lang="en">19606</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/25554" xml:lang="en">win-explorer-com-code-execution(25554)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1320" xml:lang="en">ADV-2006-1320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/17464" xml:lang="en">17464</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/24516" xml:lang="en">24516</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015897" xml:lang="en">1015897</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1764" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1764" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1191" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1191" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1679" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1679" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1448" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1448" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1743" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1743" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2006-0013">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:datacenter_64-bit:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:home"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:datacenter_64-bit:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0013</vuln:cve-id>
    <vuln:published-datetime>2006-02-14T14:06:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:10.283-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication approximated="true">SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-03-17T13:33:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:716" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:716" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:683" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:683" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1602" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1602" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1547" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1547" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1220" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1220" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/388900" xml:lang="en">VU#388900</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16636" xml:lang="en">16636</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-008.mspx" xml:lang="en">MS06-008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015630" xml:lang="en">1015630</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18857" xml:lang="en">18857</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24491" xml:lang="en">msrpc-webclient-message-bo(24491)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0577" xml:lang="en">ADV-2006-0577</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1220" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1220" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1602" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1602" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:683" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:683" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1547" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1547" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:716" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:716" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0014">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook_express:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook_express:5.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook_express:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook_express:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook_express:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:outlook_express:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook_express:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook_express:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook_express:5.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook_express:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0014</vuln:cve-id>
    <vuln:discovered-datetime>2005-09-20T00:00:00.000-04:00</vuln:discovered-datetime>
    <vuln:published-datetime>2006-04-11T20:02:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:10.377-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-04-12T14:07:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:812" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:812" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1791" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1791" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1780" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1780" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1771" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1771" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1769" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1769" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1682" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1682" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1611" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1611" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-016.mspx" xml:lang="en">MS06-016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19617" xml:lang="en">19617</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-06-007.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-06-007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1321" xml:lang="en">ADV-2006-1321</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/17459" xml:lang="en">17459</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/430645/100/0/threaded" xml:lang="en">20060411 ZDI-06-007: Microsoft Windows Address Book (WAB) File Format Parsing Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/25535" xml:lang="en">outlook-express-wab-bo(25535)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015898" xml:lang="en">1015898</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/691" xml:lang="en">691</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045003.html" xml:lang="en">20060411 ZDI-06-007: Microsoft Windows Address Book (WAB) File Format Parsing Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1611" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1611" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:812" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:812" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1771" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1771" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1791" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1791" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1780" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1780" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1769" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1769" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1682" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1682" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0015">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:frontpage_server_extensions:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_team_services"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:sharepoint_team_services</vuln:product>
      <vuln:product>cpe:/a:microsoft:frontpage_server_extensions:2002</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0015</vuln:cve-id>
    <vuln:published-datetime>2006-04-11T19:02:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:10.453-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-04-12T10:52:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1748" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1748" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/17452" xml:lang="en">17452</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS06-017.mspx" xml:lang="en">MS06-017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.argeniss.com/research/ARGENISS-ADV-040602.txt" xml:lang="en">http://www.argeniss.com/research/ARGENISS-ADV-040602.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015896" xml:lang="en">1015896</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015895" xml:lang="en">1015895</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19623" xml:lang="en">19623</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1322" xml:lang="en">ADV-2006-1322</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/430803/100/0/threaded" xml:lang="en">20060412 Vulnerability in Microsoft FrontPage Server Extensions Could Allow Cross-Site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/25537" xml:lang="en">fpse-html-xss(25537)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/704" xml:lang="en">704</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1748" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1748" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0018">
    <vuln:cve-id>CVE-2006-0018</vuln:cve-id>
    <vuln:published-datetime>2005-11-29T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:55:02.087-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-3899.  Reason: This candidate is a duplicate of CVE-2005-3899.  Notes: All CVE users should reference CVE-2005-3899 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0019">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.2.0_beta1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.2.x"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.3.x"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:kde:kde:3.3.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.2.3</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.2.x</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.3.x</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.2.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.4.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.4.0</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.2.0_beta1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.4</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.3.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.2.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.2.0</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.3.0</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.3</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.5.0</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0019</vuln:cve-id>
    <vuln:published-datetime>2006-01-20T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:10.597-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-23T10:49:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11858" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11858" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/422464/100/0/threaded" xml:lang="en">20060119 [KDE Security Advisory] kjs encodeuri/decodeuri heap overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kde.org/info/security/advisory-20060119-1.txt" xml:lang="en">http://www.kde.org/info/security/advisory-20060119-1.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18500" xml:lang="en">18500</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.3-kdelibs-kjs.diff" xml:lang="en">ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.3-kdelibs-kjs.diff</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0265" xml:lang="en">ADV-2006-0265</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-245-1" xml:lang="en">USN-245-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/422489/100/0/threaded" xml:lang="en">SUSE-SA:2006:003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2006-0184.html" xml:lang="en">RHSA-2006:0184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200601-11.xml" xml:lang="en">GLSA-200601-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-948" xml:lang="en">DSA-948</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18570" xml:lang="en">18570</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18561" xml:lang="en">18561</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18559" xml:lang="en">18559</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18552" xml:lang="en">18552</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18540" xml:lang="en">18540</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24242" xml:lang="en">kde-kjs-bo(24242)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16325" xml:lang="en">16325</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/427976/100/0/threaded" xml:lang="en">FLSA:178606</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22659" xml:lang="en">22659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:019" xml:lang="en">MDKSA-2006:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.361107" xml:lang="en">SSA:2006-045-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015512" xml:lang="en">1015512</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/364" xml:lang="en">364</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18899" xml:lang="en">18899</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18583" xml:lang="en">18583</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11858" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11858" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0020">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4::fr"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:tablet_pc"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4::fr</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:tablet_pc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0020</vuln:cve-id>
    <vuln:published-datetime>2006-01-10T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:10.687-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T08:39:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1638" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1638" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/312956" xml:lang="en">VU#312956</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-045A.html" xml:lang="en">TA06-045A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16516" xml:lang="en">16516</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-004.mspx" xml:lang="en">MS06-004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18729" xml:lang="en">18729</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0469" xml:lang="en">ADV-2006-0469</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22976" xml:lang="en">22976</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/advisory/913333.mspx" xml:lang="en">http://www.microsoft.com/technet/security/advisory/913333.mspx</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18912" xml:lang="en">18912</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://linuxbox.org/pipermail/funsec/2006-January/002828.html" xml:lang="en">[funsec] 20060110 Another WMF flaw without a Microsoft patch</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1638" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1638" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2006-0021">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:datacenter_64-bit:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::embedded"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:embedded"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:embedded</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::embedded</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:datacenter_64-bit:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0021</vuln:cve-id>
    <vuln:published-datetime>2006-02-14T14:06:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-02-28T15:06:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:678" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:678" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1662" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1662" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1647" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1647" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1425" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1425" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1310" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1310" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-045A.html" xml:lang="en">TA06-045A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/839284" xml:lang="en">VU#839284</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16645" xml:lang="en">16645</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-007.mspx" xml:lang="en">MS06-007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18853" xml:lang="en">18853</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24489" xml:lang="en">win-igmpv3-dos(24489)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0576" xml:lang="en">ADV-2006-0576</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/482658/30/4350/threaded" xml:lang="en">20071023 SYMSA-2007-012: Microsoft Windows CE IGMP Denial of Service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/exploits/5PP0T0KI0O.html" xml:lang="en">http://www.securiteam.com/exploits/5PP0T0KI0O.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/1599" xml:lang="en">1599</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015629" xml:lang="en">1015629</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1647" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1647" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1662" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1662" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:678" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:678" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1310" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1310" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1425" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1425" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the "IGMP v3 DoS Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2006-0022">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2000:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2000:sr1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2002:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2002:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2002:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2003:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2003:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2004::mac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:powerpoint:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2003:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2002:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2002:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2003:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2000:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2000:sr1</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2002:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2003</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0022</vuln:cve-id>
    <vuln:published-datetime>2006-06-13T15:06:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-04-12T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-06-14T08:00:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1984" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1984" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1836" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1836" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1069" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1069" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-164A.html" xml:lang="en">TA06-164A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/190089" xml:lang="en">VU#190089</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/18382" xml:lang="en">18382</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-028.mspx" xml:lang="en">MS06-028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/26784" xml:lang="en">powerpoint-record-bo(26784)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/2325" xml:lang="en">ADV-2006-2325</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/26435" xml:lang="en">26435</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1016287" xml:lang="en">1016287</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20633" xml:lang="en">20633</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1984" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1984" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1069" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1069" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1836" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1836" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, Office 2004 for Mac, and v. X for Mac allows user-assisted attackers to execute arbitrary code via a PowerPoint document with a malformed record, which triggers memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0023">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:tablet_pc"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:tablet_pc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0023</vuln:cve-id>
    <vuln:published-datetime>2006-02-07T21:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication approximated="true">SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-02-08T07:58:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1696" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1696" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1671" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1671" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/953860" xml:lang="en">VU#953860</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-011.mspx" xml:lang="en">MS06-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18756" xml:lang="en">18756</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24463" xml:lang="en">win-auth-users-insecure-permissions(24463)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=391523&amp;RenditionID=" xml:lang="en">http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=391523&amp;RenditionID=</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0417" xml:lang="en">ADV-2006-0417</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/423587/100/0/threaded" xml:lang="en">20060131 Windows Access Control Demystified</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/advisory/914457.mspx" xml:lang="en">http://www.microsoft.com/technet/security/advisory/914457.mspx</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf" xml:lang="en">http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015765" xml:lang="en">1015765</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015595" xml:lang="en">1015595</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19313" xml:lang="en">19313</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19238" xml:lang="en">19238</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1671" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1671" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1696" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1696" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs."  NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0024">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:4.0_r12"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:5.0_r50"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:6.0.29.0"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:6.0.40.0"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:6.0.47.0"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:6.0.65.0"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:6.0.79.0"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:7.0.19.0"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:7.0.60.0"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:7.0.61.0"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:7.0_r19"/>
        <cpe-lang:fact-ref name="cpe:/a:macromedia:flash_player:8.0.22.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:macromedia:flash_player:7.0_r19</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:6.0.65.0</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:8.0.22.0</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:6.0.40.0</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:5.0_r50</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:6.0.29.0</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:6.0.79.0</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:7.0.19.0</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:7.0.60.0</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:6.0</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:5.0</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:7.0.61.0</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:4.0_r12</vuln:product>
      <vuln:product>cpe:/a:macromedia:flash_player:6.0.47.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0024</vuln:cve-id>
    <vuln:published-datetime>2006-03-15T11:06:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:11.110-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-03-16T09:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1922" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1922" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1894" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1894" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-352A.html" xml:lang="en">TA07-352A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" xml:lang="en">TA06-132A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-129A.html" xml:lang="en">TA06-129A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-075A.html" xml:lang="en">TA06-075A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/945060" xml:lang="en">VU#945060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.macromedia.com/devnet/security/security_zone/apsb06-03.html" xml:lang="en">http://www.macromedia.com/devnet/security/security_zone/apsb06-03.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19218" xml:lang="en">19218</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/25005" xml:lang="en">macromedia-swf-code-execution(25005)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/4238" xml:lang="en">ADV-2007-4238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1779" xml:lang="en">ADV-2006-1779</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1744" xml:lang="en">ADV-2006-1744</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1262" xml:lang="en">ADV-2006-1262</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0952" xml:lang="en">ADV-2006-0952</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/17106" xml:lang="en">17106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2006-0268.html" xml:lang="en">RHSA-2006:0268</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/23908" xml:lang="en">23908</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/17951" xml:lang="en">17951</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.opera.com/docs/changelogs/windows/854/" xml:lang="en">http://www.opera.com/docs/changelogs/windows/854/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2006_15_flashplayer.html" xml:lang="en">SUSE-SA:2006:015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-020.mspx" xml:lang="en">MS06-020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200603-20.xml" xml:lang="en">GLSA-200603-20</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015770" xml:lang="en">1015770</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28136" xml:lang="en">28136</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20077" xml:lang="en">20077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20045" xml:lang="en">20045</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19328" xml:lang="en">19328</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19259" xml:lang="en">19259</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19198" xml:lang="en">19198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html" xml:lang="en">APPLE-SA-2007-12-17</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" xml:lang="en">APPLE-SA-2006-05-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307179" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307179</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1894" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1894" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1922" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1922" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple unspecified vulnerabilities in Adobe Flash Player 8.0.22.0 and earlier allow remote attackers to execute arbitrary code via a crafted SWF file.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0025">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_player:10"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_player:9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:windows_media_player:10</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_media_player:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0025</vuln:cve-id>
    <vuln:discovered-datetime>2006-02-22T00:00:00.000-05:00</vuln:discovered-datetime>
    <vuln:published-datetime>2006-06-13T15:06:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:11.250-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-06-14T07:52:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1974" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1974" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1820" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1820" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1807" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1807" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1805" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1805" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1729" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1729" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1230" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1230" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-164A.html" xml:lang="en">TA06-164A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/608020" xml:lang="en">VU#608020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/18385" xml:lang="en">18385</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-024.mspx" xml:lang="en">MS06-024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=406" xml:lang="en">20060613 Windows Media Player PNG Chunk Decoding Stack-Based Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20626" xml:lang="en">20626</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/26788" xml:lang="en">win-media-player-png-bo(26788)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/2322" xml:lang="en">ADV-2006-2322</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/26430" xml:lang="en">26430</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1016284" xml:lang="en">1016284</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1807" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1807" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1974" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1974" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1230" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1230" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1820" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1820" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1729" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1729" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1805" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1805" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0026">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:5.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0026</vuln:cve-id>
    <vuln:published-datetime>2006-07-11T18:05:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:11.347-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication approximated="true">SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-07-12T11:38:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:435" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:435" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/395588" xml:lang="en">VU#395588</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-192A.html" xml:lang="en">TA06-192A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/26796" xml:lang="en">iis-asp-bo(26796)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/18858" xml:lang="en">18858</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-034.mspx" xml:lang="en">MS06-034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1016466" xml:lang="en">1016466</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/21006" xml:lang="en">21006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/2752" xml:lang="en">ADV-2006-2752</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/27152" xml:lang="en">27152</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2006-07/0316.html" xml:lang="en">20060718 ASP.DLL Include File Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:435" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:435" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP).</vuln:summary>
  </entry>
  <entry id="CVE-2006-0027">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2003:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2003:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:exchange_server:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2003:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0027</vuln:cve-id>
    <vuln:published-datetime>2006-05-09T22:10:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-04-15T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-05-10T10:47:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2035" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2035" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1996" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1996" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1818" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1818" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-129A.html" xml:lang="en">TA06-129A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/303452" xml:lang="en">VU#303452</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-019.mspx" xml:lang="en">MS06-019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/25556" xml:lang="en">exchange-calendar-code-execution(25556)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1743" xml:lang="en">ADV-2006-1743</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/17908" xml:lang="en">17908</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/25338" xml:lang="en">25338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1016048" xml:lang="en">1016048</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20029" xml:lang="en">20029</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2035" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2035" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1996" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1996" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1818" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1818" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0028">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2004::mac_os_x"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:x::mac_os_x"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:v.x::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:x::mac_os_x</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:v.x::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2004::mac_os_x</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0028</vuln:cve-id>
    <vuln:published-datetime>2006-03-14T18:02:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-04-18T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-03-16T08:44:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1635" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1635" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1509" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1509" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1411" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1411" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1158" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1158" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-073A.html" xml:lang="en">TA06-073A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/339878" xml:lang="en">VU#339878</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx" xml:lang="en">MS06-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015766" xml:lang="en">1015766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19138" xml:lang="en">19138</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/25225" xml:lang="en">excel-parsing-format-file-bo(25225)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-06-004.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-06-004.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0950" xml:lang="en">ADV-2006-0950</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/427632/100/0/threaded" xml:lang="en">20060314 ZDI-06-004: Microsoft Excel File Format Parsing Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/23899" xml:lang="en">23899</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/583" xml:lang="en">583</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19238" xml:lang="en">19238</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1411" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1411" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1635" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1635" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1158" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1158" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1509" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1509" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0029">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2004::mac_os_x"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:x::mac_os_x"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:v.x::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:x::mac_os_x</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:v.x::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2004::mac_os_x</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0029</vuln:cve-id>
    <vuln:published-datetime>2006-03-14T18:02:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-04-15T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-03-16T08:52:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1633" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1633" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1579" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1579" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1570" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1570" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1522" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1522" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-073A.html" xml:lang="en">TA06-073A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/235774" xml:lang="en">VU#235774</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx" xml:lang="en">MS06-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015766" xml:lang="en">1015766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19138" xml:lang="en">19138</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/25227" xml:lang="en">excel-description-bo(25227)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0950" xml:lang="en">ADV-2006-0950</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/23900" xml:lang="en">23900</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/586" xml:lang="en">586</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/585" xml:lang="en">585</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19238" xml:lang="en">19238</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1570" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1570" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1522" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1522" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1579" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1579" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1633" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1633" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0030">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2004::mac_os_x"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:x::mac_os_x"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:v.x::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:x::mac_os_x</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:v.x::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2004::mac_os_x</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0030</vuln:cve-id>
    <vuln:published-datetime>2006-03-14T18:02:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-03-16T08:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1666" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1666" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1630" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1630" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1510" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1510" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1401" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1401" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-073A.html" xml:lang="en">TA06-073A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/123222" xml:lang="en">VU#123222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx" xml:lang="en">MS06-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015766" xml:lang="en">1015766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19138" xml:lang="en">19138</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/25229" xml:lang="en">excel-graphic-bo(25229)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0950" xml:lang="en">ADV-2006-0950</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16181" xml:lang="en">16181</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/23901" xml:lang="en">23901</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19238" xml:lang="en">19238</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1630" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1630" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1510" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1510" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1401" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1401" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1666" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1666" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0031">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:v.x::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:v.x::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0031</vuln:cve-id>
    <vuln:published-datetime>2006-03-14T18:02:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-03-16T08:54:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:763" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:763" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1750" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1750" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1525" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1525" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1327" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1327" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-073A.html" xml:lang="en">TA06-073A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/104302" xml:lang="en">VU#104302</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/17101" xml:lang="en">17101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx" xml:lang="en">MS06-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015766" xml:lang="en">1015766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19138" xml:lang="en">19138</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/25228" xml:lang="en">excel-record-bo(25228)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0950" xml:lang="en">ADV-2006-0950</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/427699/100/0/threaded" xml:lang="en">20060315 [xfocus-SD-060314]Microsoft Office Excel Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/23902" xml:lang="en">23902</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/589" xml:lang="en">589</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19238" xml:lang="en">19238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/1521.html" xml:lang="en">20060314 [xfocus-SD-060314]Microsoft Office Excel Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1327" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1327" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1750" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1750" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:763" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:763" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1525" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1525" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0032">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:resource_kit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:datacenter_edition"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:datacenter_edition:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:datacenter_edition:sp1_beta_1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:datacenter_edition_itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:datacenter_edition_itanium:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:datacenter_edition_itanium:sp1_beta_1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_edition:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_edition:sp1_beta_1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_edition_itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_edition_itanium:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_edition_itanium:sp1_beta_1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::enterprise"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard:sp1_beta_1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web:sp1_beta_1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:datacenter_edition_itanium:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_edition_itanium:sp1_beta_1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard:sp1_beta_1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:datacenter_edition_itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:datacenter_edition_itanium:sp1_beta_1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:datacenter_edition</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web:sp1_beta_1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:resource_kit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1::enterprise</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_edition:sp1_beta_1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_edition_itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_edition:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:datacenter_edition:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_edition_itanium:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:datacenter_edition:sp1_beta_1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:advanced_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0032</vuln:cve-id>
    <vuln:published-datetime>2006-09-12T19:07:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:12.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-09-13T13:15:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:535" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:535" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-255A.html" xml:lang="en">TA06-255A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/108884" xml:lang="en">VU#108884</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/19927" xml:lang="en">19927</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS06-053.mspx" xml:lang="en">MS06-053</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/21861" xml:lang="en">21861</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/28651" xml:lang="en">ms-indexing-service-xss(28651)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/3564" xml:lang="en">ADV-2006-3564</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/447511/100/0/threaded" xml:lang="en">20061001 Microsoft Internet Information Services UTF-7 XSS Vulnerability [MS06-053]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/447509/100/0/threaded" xml:lang="en">20061002 IE UXSS (Universal XSS in IE, was Re: Microsoft Internet Information Services UTF-7 XSS Vulnerability [MS06-053])</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/446630/100/100/threaded" xml:lang="en">SSRT061187</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/446630/100/100/threaded" xml:lang="en">HPSBST02134</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.geocities.jp/ptrs_sec/advisory09e.html" xml:lang="en">http://www.geocities.jp/ptrs_sec/advisory09e.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1016826" xml:lang="en">1016826</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:535" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:535" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0033">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0033</vuln:cve-id>
    <vuln:published-datetime>2006-07-11T17:05:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-04-12T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-07-12T11:24:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:163" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:163" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-192A.html" xml:lang="en">TA06-192A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/459388" xml:lang="en">VU#459388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/18913" xml:lang="en">18913</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-039.mspx" xml:lang="en">MS06-039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/2757" xml:lang="en">ADV-2006-2757</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/27147" xml:lang="en">27147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-22.html" xml:lang="en">http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-22.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1016470" xml:lang="en">1016470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/21013" xml:lang="en">21013</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:163" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:163" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0034">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:distributed_transaction_coordinator"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::embedded"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:embedded"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::embedded</vuln:product>
      <vuln:product>cpe:/a:microsoft:distributed_transaction_coordinator</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:embedded</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6:workstation</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp6</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:advanced_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0034</vuln:cve-id>
    <vuln:discovered-datetime>2005-10-11T00:00:00.000-04:00</vuln:discovered-datetime>
    <vuln:published-datetime>2006-05-09T22:14:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-10-17T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-05-10T10:54:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1908" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1908" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1477" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1477" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1222" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1222" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/17906" xml:lang="en">17906</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/433430/100/0/threaded" xml:lang="en">20060509 [EEYEB20051011A] - Microsoft Distributed Transaction Coordinator Heap Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms06-018.mspx" xml:lang="en">MS06-018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.eeye.com/html/research/advisories/AD20060509a.html" xml:lang="en">http://www.eeye.com/html/research/advisories/AD20060509a.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20000" xml:lang="en">20000</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/25559" xml:lang="en">msdtc-network-message-dos(25559)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1742" xml:lang="en">ADV-2006-1742</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/433677/100/0/threaded" xml:lang="en">20060511 Microsoft MSDTC NdrAllocate Validation Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/25335" xml:lang="en">25335</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1016047" xml:lang="en">1016047</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/863" xml:lang="en">863</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0269.html" xml:lang="en">20060510 Microsoft MSDTC NdrAllocate Validation Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0238.html" xml:lang="en">20060509 [EEYEB20051011A] - Microsoft Distributed Transaction Coordinator Heap Overflow</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1477" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1477" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1222" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1222" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1908" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1908" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, which triggers a bug in the NdrAllocate function, aka the MSDTC Invalid Memory Access Vulnerability.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0035">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0035</vuln:cve-id>
    <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-03-19T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T16:08:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2006/0004" xml:lang="en">2006-0004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18482" xml:lang="en">18482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24202" xml:lang="en">kernel-afnetlink-dos(24202)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0220" xml:lang="en">ADV-2006-0220</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16414" xml:lang="en">16414</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ad8e4b75c8a7bed475d72ce09bf5267188621961" xml:lang="en">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ad8e4b75c8a7bed475d72ce09bf5267188621961</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/388" xml:lang="en">388</vuln:reference>
    </vuln:references>
    <vuln:summary>The netlink_rcv_skb function in af_netlink.c in Linux kernel 2.6.14 and 2.6.15 allows local users to cause a denial of service (infinite loop) via a nlmsg_len field of 0.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0036">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0036</vuln:cve-id>
    <vuln:published-datetime>2006-01-23T17:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:12.470-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-24T07:56:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0220" xml:lang="en">ADV-2006-0220</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=15db34702cfafd24acc60295cf14861e497502ab" xml:lang="en">http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=15db34702cfafd24acc60295cf14861e497502ab</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24203" xml:lang="en">kernel-pptpincallrequest-dos(24203)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2006/0004" xml:lang="en">2006-0004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16414" xml:lang="en">16414</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/388" xml:lang="en">388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18482" xml:lang="en">18482</vuln:reference>
    </vuln:references>
    <vuln:summary>ip_nat_pptp in the PPTP NAT helper (netfilter/ip_nat_helper_pptp.c) in Linux kernel 2.6.14, and other versions, allows remote attackers to cause a denial of service (memory corruption or crash) via an inbound PPTP_IN_CALL_REQUEST packet that causes a null pointer to be used in an offset calculation.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0037">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0037</vuln:cve-id>
    <vuln:published-datetime>2006-01-23T17:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:12.563-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-24T07:55:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0220" xml:lang="en">ADV-2006-0220</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=03b9feca89366952ae5dfe4ad8107b1ece50b710" xml:lang="en">http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=03b9feca89366952ae5dfe4ad8107b1ece50b710</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24204" xml:lang="en">kernel-pptpnathelper-dos(24204)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2006/0004" xml:lang="en">2006-0004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16414" xml:lang="en">16414</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/388" xml:lang="en">388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18482" xml:lang="en">18482</vuln:reference>
    </vuln:references>
    <vuln:summary>ip_nat_pptp in the PPTP NAT helper (netfilter/ip_nat_helper_pptp.c) in Linux kernel 2.6.14, and other versions, allows local users to cause a denial of service (memory corruption or crash) via a crafted outbound packet that causes an incorrect offset to be calculated from pointer arithmetic when non-linear SKBs (socket buffers) are used.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0038">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:2.6.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6_test9_cvs"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.7:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:2.6.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6_test9_cvs</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.6:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0038</vuln:cve-id>
    <vuln:published-datetime>2006-03-22T15:06:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:12.627-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-03-23T12:48:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10945" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10945" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/17178" xml:lang="en">17178</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=186295" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=186295</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/25400" xml:lang="en">linux-netfilter-doreplace-overflow(25400)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/2554" xml:lang="en">ADV-2006-2554</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1046" xml:lang="en">ADV-2006-1046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-302-1" xml:lang="en">USN-302-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2006-0575.html" xml:lang="en">RHSA-2006:0575</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ee4bb818ae35f68d1f848eae0a7b150a38eb4168" xml:lang="en">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ee4bb818ae35f68d1f848eae0a7b150a38eb4168</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1103" xml:lang="en">DSA-1103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1097" xml:lang="en">DSA-1097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/22417" xml:lang="en">22417</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/21465" xml:lang="en">21465</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20914" xml:lang="en">20914</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20716" xml:lang="en">20716</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20671" xml:lang="en">20671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19330" xml:lang="en">19330</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10945" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10945" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer overflow in the do_replace function in netfilter for Linux before 2.6.16-rc3, when using "virtualization solutions" such as OpenVZ, allows local users with CAP_NET_ADMIN rights to cause a buffer overflow in the copy_from_user function.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0039">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0039</vuln:cve-id>
    <vuln:discovered-datetime>2006-05-16T00:00:00.000-04:00</vuln:discovered-datetime>
    <vuln:published-datetime>2006-05-19T18:02:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:12.750-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-05-22T09:31:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10309" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10309" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-362"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2722971cbe831117686039d5c334f2c0f560be13" xml:lang="en">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2722971cbe831117686039d5c334f2c0f560be13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.gentoo.org/show_bug.cgi?id=133465" xml:lang="en">http://bugs.gentoo.org/show_bug.cgi?id=133465</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=191698" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=191698</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/26583" xml:lang="en">linux-doaddcounters-race-condition(26583)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/2554" xml:lang="en">ADV-2006-2554</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1893" xml:lang="en">ADV-2006-1893</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-311-1" xml:lang="en">USN-311-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/18113" xml:lang="en">18113</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2006-0689.html" xml:lang="en">RHSA-2006:0689</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/25697" xml:lang="en">25697</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1103" xml:lang="en">DSA-1103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1097" xml:lang="en">DSA-1097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2006-249.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2006-249.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/22945" xml:lang="en">22945</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/22292" xml:lang="en">22292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/21476" xml:lang="en">21476</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20991" xml:lang="en">20991</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20914" xml:lang="en">20914</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20671" xml:lang="en">20671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20185" xml:lang="en">20185</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.17" xml:lang="en">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.17</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10309" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10309" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Race condition in the do_add_counters function in netfilter for Linux kernel 2.6.16 allows local users with CAP_NET_ADMIN capabilities to read kernel memory by triggering the race condition in a way that produces a size value that is inconsistent with allocated memory, which leads to a buffer over-read in IPT_ENTRY_ITERATE.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0040">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnome:evolution:2.4.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnome:evolution:2.4.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0040</vuln:cve-id>
    <vuln:published-datetime>2006-03-09T20:02:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:12.830-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-03-10T15:23:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0801" xml:lang="en">ADV-2006-0801</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/426452/100/0/threaded" xml:lang="en">20060301 Evolution Emailer DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/25050" xml:lang="en">evolution-email-dos(25050)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16899" xml:lang="en">16899</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19094" xml:lang="en">19094</vuln:reference>
    </vuln:references>
    <vuln:summary>GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large number of URLs, possibly due to unknown problems in gtkhtml.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0042">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:libapreq2:libapreq2:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:libapreq2:libapreq2:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:libapreq2:libapreq2:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:libapreq2:libapreq2:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:libapreq2:libapreq2:1.33"/>
        <cpe-lang:fact-ref name="cpe:/a:libapreq2:libapreq2:2.01_dev"/>
        <cpe-lang:fact-ref name="cpe:/a:libapreq2:libapreq2:2.02_dev"/>
        <cpe-lang:fact-ref name="cpe:/a:libapreq2:libapreq2:2.03_dev"/>
        <cpe-lang:fact-ref name="cpe:/a:libapreq2:libapreq2:2.04_dev"/>
        <cpe-lang:fact-ref name="cpe:/a:libapreq2:libapreq2:2.05_dev"/>
        <cpe-lang:fact-ref name="cpe:/a:libapreq2:libapreq2:2.06_dev"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:libapreq2:libapreq2:1.33</vuln:product>
      <vuln:product>cpe:/a:libapreq2:libapreq2:2.05_dev</vuln:product>
      <vuln:product>cpe:/a:libapreq2:libapreq2:1.0</vuln:product>
      <vuln:product>cpe:/a:libapreq2:libapreq2:2.04_dev</vuln:product>
      <vuln:product>cpe:/a:libapreq2:libapreq2:1.2</vuln:product>
      <vuln:product>cpe:/a:libapreq2:libapreq2:2.03_dev</vuln:product>
      <vuln:product>cpe:/a:libapreq2:libapreq2:1.3</vuln:product>
      <vuln:product>cpe:/a:libapreq2:libapreq2:1.1</vuln:product>
      <vuln:product>cpe:/a:libapreq2:libapreq2:2.06_dev</vuln:product>
      <vuln:product>cpe:/a:libapreq2:libapreq2:2.02_dev</vuln:product>
      <vuln:product>cpe:/a:libapreq2:libapreq2:2.01_dev</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0042</vuln:cve-id>
    <vuln:published-datetime>2006-02-18T16:02:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-05-19T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-02-23T10:27:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16710" xml:lang="en">16710</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1000" xml:lang="en">DSA-1000</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19139" xml:lang="en">19139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18846" xml:lang="en">18846</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24917" xml:lang="en">libapreq2-parsing-dos(24917)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0645" xml:lang="en">ADV-2006-0645</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200604-08.xml" xml:lang="en">GLSA-200604-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.apache.org/viewcvs.cgi/httpd/apreq/tags/v2_07/CHANGES?rev=376998&amp;view=markup" xml:lang="en">http://svn.apache.org/viewcvs.cgi/httpd/apreq/tags/v2_07/CHANGES?rev=376998&amp;view=markup</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/737" xml:lang="en">737</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19658" xml:lang="en">19658</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in (1) apreq_parse_headers and (2) apreq_parse_urlencoded functions in Apache2::Request (Libapreq2) before 2.07 allows remote attackers cause a denial of service (CPU consumption) via unknown attack vectors that result in quadratic computational complexity.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0043">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:10.0::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.1::personal"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.1::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.1::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.2::personal"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.2::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.2::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.3::personal"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.3::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.3::x86_64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:suse:suse_linux:9.1::personal</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.3::x86_64</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.1::professional</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:1.0</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.2::professional</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.3::personal</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.3::professional</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.2::personal</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.1::x86_64</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:10.0::professional</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:9.2::x86_64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0043</vuln:cve-id>
    <vuln:published-datetime>2006-01-30T21:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:12.987-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-31T10:10:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18638" xml:lang="en">18638</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2006-Jan/0007.html" xml:lang="en">SUSE-SA:2006:005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24347" xml:lang="en">nfs-rpcmountd-realpath-bo(24347)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0348" xml:lang="en">ADV-2006-0348</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16388" xml:lang="en">16388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18614" xml:lang="en">18614</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-975" xml:lang="en">DSA-975</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18889" xml:lang="en">18889</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350020" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350020</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the realpath function in nfs-server rpc.mountd, as used in SUSE Linux 9.1 through 10.0, allows local users to execute arbitrary code via unspecified vectors involving mount requests and symlinks.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0044">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:albatross:albatross:1.00"/>
        <cpe-lang:fact-ref name="cpe:/a:albatross:albatross:1.01"/>
        <cpe-lang:fact-ref name="cpe:/a:albatross:albatross:1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:albatross:albatross:1.20"/>
        <cpe-lang:fact-ref name="cpe:/a:albatross:albatross:1.30"/>
        <cpe-lang:fact-ref name="cpe:/a:albatross:albatross:1.32"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:albatross:albatross:1.32</vuln:product>
      <vuln:product>cpe:/a:albatross:albatross:1.00</vuln:product>
      <vuln:product>cpe:/a:albatross:albatross:1.01</vuln:product>
      <vuln:product>cpe:/a:albatross:albatross:1.30</vuln:product>
      <vuln:product>cpe:/a:albatross:albatross:1.20</vuln:product>
      <vuln:product>cpe:/a:albatross:albatross:1.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0044</vuln:cve-id>
    <vuln:published-datetime>2006-01-17T20:51:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:13.220-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-18T09:57:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-942" xml:lang="en">DSA-942</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18457" xml:lang="en">18457</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0196" xml:lang="en">ADV-2006-0196</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16252" xml:lang="en">16252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.object-craft.com.au/projects/albatross/news.html" xml:lang="en">http://www.object-craft.com.au/projects/albatross/news.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security.debian.org/pool/updates/main/a/albatross/albatross_1.20-2.diff.gz" xml:lang="en">http://security.debian.org/pool/updates/main/a/albatross/albatross_1.20-2.diff.gz</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24130" xml:lang="en">albatross-context-command-execution(24130)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22451" xml:lang="en">22451</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18496" xml:lang="en">18496</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in context.py in Albatross web application toolkit before 1.33 allows remote attackers to execute arbitrary commands via unspecified vectors involving template files and the "handling of submitted form fields".</vuln:summary>
  </entry>
  <entry id="CVE-2006-0045">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:linley_henzell:dungeon_crawl:4.0.0_b23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:linley_henzell:dungeon_crawl:4.0.0_b23</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0045</vuln:cve-id>
    <vuln:published-datetime>2006-01-20T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:13.313-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-23T11:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-949" xml:lang="en">DSA-949</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0303" xml:lang="en">ADV-2006-0303</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16337" xml:lang="en">16337</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18545" xml:lang="en">18545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24262" xml:lang="en">crawl-insecure-command-execution(24262)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22690" xml:lang="en">22690</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18573" xml:lang="en">18573</vuln:reference>
    </vuln:references>
    <vuln:summary>crawl before 4.0.0 does not securely call programs when saving and loading games, which allows local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0046">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cameron_simpson:adzapper:2006-01-01"/>
        <cpe-lang:fact-ref name="cpe:/a:cameron_simpson:adzapper:2006-01-05"/>
        <cpe-lang:fact-ref name="cpe:/a:cameron_simpson:adzapper:2006-01-07"/>
        <cpe-lang:fact-ref name="cpe:/a:cameron_simpson:adzapper:2006-01-14"/>
        <cpe-lang:fact-ref name="cpe:/a:cameron_simpson:adzapper:2006-01-15"/>
        <cpe-lang:fact-ref name="cpe:/a:cameron_simpson:adzapper:2006-01-23"/>
        <cpe-lang:fact-ref name="cpe:/a:cameron_simpson:adzapper:2006-01-24"/>
        <cpe-lang:fact-ref name="cpe:/a:cameron_simpson:adzapper:2006-01-25"/>
        <cpe-lang:fact-ref name="cpe:/a:cameron_simpson:adzapper:2006-01-28"/>
        <cpe-lang:fact-ref name="cpe:/a:cameron_simpson:adzapper:2006-01-29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cameron_simpson:adzapper:2006-01-14</vuln:product>
      <vuln:product>cpe:/a:cameron_simpson:adzapper:2006-01-23</vuln:product>
      <vuln:product>cpe:/a:cameron_simpson:adzapper:2006-01-25</vuln:product>
      <vuln:product>cpe:/a:cameron_simpson:adzapper:2006-01-01</vuln:product>
      <vuln:product>cpe:/a:cameron_simpson:adzapper:2006-01-29</vuln:product>
      <vuln:product>cpe:/a:cameron_simpson:adzapper:2006-01-24</vuln:product>
      <vuln:product>cpe:/a:cameron_simpson:adzapper:2006-01-28</vuln:product>
      <vuln:product>cpe:/a:cameron_simpson:adzapper:2006-01-07</vuln:product>
      <vuln:product>cpe:/a:cameron_simpson:adzapper:2006-01-15</vuln:product>
      <vuln:product>cpe:/a:cameron_simpson:adzapper:2006-01-05</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0046</vuln:cve-id>
    <vuln:published-datetime>2006-02-13T06:06:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:13.393-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-02-13T08:11:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-966" xml:lang="en">DSA-966</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18777" xml:lang="en">18777</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18771" xml:lang="en">18771</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0491" xml:lang="en">ADV-2006-0491</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350308" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi/squid_redirect.diff?bug=350308;msg=5;att=1" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi/squid_redirect.diff?bug=350308;msg=5;att=1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://adzapper.sourceforge.net/cvslog.html" xml:lang="en">http://adzapper.sourceforge.net/cvslog.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24640" xml:lang="en">adzapper-squid-redirect-dos(24640)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16558" xml:lang="en">16558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22900" xml:lang="en">22900</vuln:reference>
    </vuln:references>
    <vuln:summary>squid_redirect script in adzapper before 2006-01-29 allows remote attackers to cause a denial of service (CPU consumption) via a URL with a large number of trailing / (forward slashes), which might produce inefficient regular expressions.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0047">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:freeciv:freeciv:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:freeciv:freeciv:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:freeciv:freeciv:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:freeciv:freeciv:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:freeciv:freeciv:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:freeciv:freeciv:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:freeciv:freeciv:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:freeciv:freeciv:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:freeciv:freeciv:2.0.7a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:freeciv:freeciv:2.0.3</vuln:product>
      <vuln:product>cpe:/a:freeciv:freeciv:2.0.5</vuln:product>
      <vuln:product>cpe:/a:freeciv:freeciv:2.0.7</vuln:product>
      <vuln:product>cpe:/a:freeciv:freeciv:2.0.6</vuln:product>
      <vuln:product>cpe:/a:freeciv:freeciv:2.0.0</vuln:product>
      <vuln:product>cpe:/a:freeciv:freeciv:2.0.4</vuln:product>
      <vuln:product>cpe:/a:freeciv:freeciv:2.0.7a</vuln:product>
      <vuln:product>cpe:/a:freeciv:freeciv:2.0.2</vuln:product>
      <vuln:product>cpe:/a:freeciv:freeciv:2.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0047</vuln:cve-id>
    <vuln:published-datetime>2006-03-07T06:02:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-08-25T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-03-08T08:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16975" xml:lang="en">16975</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/426866/100/0/threaded" xml:lang="en">20060306 Out of memory crash in Freeciv 2.0.7</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19120" xml:lang="en">19120</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/25166" xml:lang="en">freeciv-packets-dos(25166)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0838" xml:lang="en">ADV-2006-0838</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:053" xml:lang="en">MDKSA-2006:053</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200603-11.xml" xml:lang="en">GLSA-200603-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-994" xml:lang="en">DSA-994</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19253" xml:lang="en">19253</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19227" xml:lang="en">19227</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=355211" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=355211</vuln:reference>
    </vuln:references>
    <vuln:summary>packets.c in Freeciv 2.0 before 2.0.8 allows remote attackers to cause a denial of service (server crash) via crafted packets with negative compressed size values.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0048">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:francesco_stablum:tcpick:0.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:francesco_stablum:tcpick:0.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0048</vuln:cve-id>
    <vuln:published-datetime>2006-04-25T20:06:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:13.580-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-04-27T09:42:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1466" xml:lang="en">ADV-2006-1466</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/17665" xml:lang="en">17665</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://sourceforge.net/mailarchive/forum.php?thread_id=9989610&amp;forum_id=37151" xml:lang="en">http://sourceforge.net/mailarchive/forum.php?thread_id=9989610&amp;forum_id=37151</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/26090" xml:lang="en">tcpick-writec-dos(26090)</vuln:reference>
    </vuln:references>
    <vuln:summary>Francesco Stablum tcpick 0.2.1 allows remote attackers to cause a denial of service (segmentation fault) via certain fragmented packets, possibly involving invalid headers and an attacker-controlled payload length.  NOTE: this issue might be a buffer overflow or overread.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0049">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.0.3b"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.2.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:privacy_guard:1.4.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.0.2</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.3.4</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.0.3</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.3.3</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.4.2</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.0.7</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.0.5</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.2.1</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.4.2.1</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.0.3b</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.2.4</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.4.1</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.0.6</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.0.4</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.2.6</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.0</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.2.5</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.4</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.0.1</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.2</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.2.3</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.2.2</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.2.7</vuln:product>
      <vuln:product>cpe:/a:gnu:privacy_guard:1.2.2:rc1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0049</vuln:cve-id>
    <vuln:published-datetime>2006-03-13T16:06:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:13.687-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-03-14T07:55:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10063" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10063" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/17058" xml:lang="en">17058</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/427324/100/0/threaded" xml:lang="en">20060309 GnuPG does not detect injection of unsigned data</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/23790" xml:lang="en">23790</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200603-08.xml" xml:lang="en">GLSA-200603-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-993" xml:lang="en">DSA-993</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015749" xml:lang="en">1015749</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19173" xml:lang="en">19173</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.gnupg.org/pipermail/gnupg-announce/2006q1/000216.html" xml:lang="en">[gnupg-announce] 20060309 [Announce] GnuPG does not detect injection of unsigned data</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0915" xml:lang="en">ADV-2006-0915</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntulinux.org/support/documentation/usn/usn-264-1" xml:lang="en">USN-264-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/25184" xml:lang="en">gnupg-nondetached-sig-verification(25184)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2006/0014" xml:lang="en">2006-0014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.476477" xml:lang="en">SSA:2006-072-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/433931/100/0/threaded" xml:lang="en">FLSA-2006:185355</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2006-0266.html" xml:lang="en">RHSA-2006:0266</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00021.html" xml:lang="en">FEDORA-2006-147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:055" xml:lang="en">MDKSA-2006:055</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/568" xml:lang="en">568</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/450" xml:lang="en">450</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19532" xml:lang="en">19532</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19287" xml:lang="en">19287</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19249" xml:lang="en">19249</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19244" xml:lang="en">19244</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19234" xml:lang="en">19234</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19232" xml:lang="en">19232</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19231" xml:lang="en">19231</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19203" xml:lang="en">19203</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19197" xml:lang="en">19197</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.de/archive/suse-security-announce/2006-Mar/0003.html" xml:lang="en">SUSE-SA:2006:014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U" xml:lang="en">20060401-01-U</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10063" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10063" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that is not associated with a control packet, which causes the check for concatenated signatures to report that the signature is valid, a different vulnerability than CVE-2006-0455.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0050">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::arm"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::hppa"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ia-32"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ia-64"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::m68k"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::mips"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::mipsel"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::s-390"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::amd64"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::arm"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::hppa"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::ia-32"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::ia-64"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::m68k"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::mips"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::mipsel"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::s-390"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::sparc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::sparc</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::ia-64</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::mips</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ia-32</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::s-390</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::s-390</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::mipsel</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::alpha</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::ppc</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::arm</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::mips</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::mipsel</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::hppa</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::m68k</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ppc</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::hppa</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::alpha</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::m68k</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ia-64</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::arm</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::amd64</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::ia-32</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::sparc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0050</vuln:cve-id>
    <vuln:published-datetime>2006-03-23T06:06:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:13.780-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>1.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-03-23T13:30:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1013" xml:lang="en">DSA-1013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19318" xml:lang="en">19318</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/17182" xml:lang="en">17182</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/25442" xml:lang="en">snmptrapfmt-log-temprary-file(25442)</vuln:reference>
    </vuln:references>
    <vuln:summary>snmptrapfmt in Debian 3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary log file.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0051">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:kaffeine:kaffeine_player:0.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:kaffeine:kaffeine_player:0.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:kaffeine:kaffeine_player:0.4.3b"/>
        <cpe-lang:fact-ref name="cpe:/a:kaffeine:kaffeine_player:0.5_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:kaffeine:kaffeine_player:0.7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kaffeine:kaffeine_player:0.4.3b</vuln:product>
      <vuln:product>cpe:/a:kaffeine:kaffeine_player:0.5_rc1</vuln:product>
      <vuln:product>cpe:/a:kaffeine:kaffeine_player:0.7.1</vuln:product>
      <vuln:product>cpe:/a:kaffeine:kaffeine_player:0.4.3</vuln:product>
      <vuln:product>cpe:/a:kaffeine:kaffeine_player:0.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0051</vuln:cve-id>
    <vuln:published-datetime>2006-04-05T06:04:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:13.860-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-04-05T09:06:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kde.org/info/security/advisory-20060404-1.txt" xml:lang="en">http://www.kde.org/info/security/advisory-20060404-1.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19525" xml:lang="en">19525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/25631" xml:lang="en">kaffeine-http-peek-bo(25631)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1229" xml:lang="en">ADV-2006-1229</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntulinux.org/support/documentation/usn/usn-268-1" xml:lang="en">USN-268-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/17372" xml:lang="en">17372</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/430319/100/0/threaded" xml:lang="en">20060405 [Kaffeine Security Advisory] Heap based buffer overflow in http_peek()</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2006_08_sr.html" xml:lang="en">SUSE-SR:2006:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200604-04.xml" xml:lang="en">GLSA-200604-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1023" xml:lang="en">DSA-1023</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015863" xml:lang="en">1015863</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19571" xml:lang="en">19571</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19557" xml:lang="en">19557</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19549" xml:lang="en">19549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19542" xml:lang="en">19542</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19540" xml:lang="en">19540</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:065" xml:lang="en">MDKSA-2006:065</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in playlistimport.cpp in Kaffeine Player 0.4.2 through 0.7.1 allows user-assisted attackers to execute arbitrary code via long HTTP request headers when Kaffeine is "fetching remote playlists", which triggers the overflow in the http_peek function.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0052">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.0:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:mailman:2.1b1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:mailman:2.0:beta4</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.1.1</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.1</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.1.2</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.6</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.14</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.10</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.13</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.1.4</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:1.0</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.4</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0:beta5</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.9</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.1.3</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.2</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.11</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.8</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0:beta3</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.1b1</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.3</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.1.5</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:1.1</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.7</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.1</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.5</vuln:product>
      <vuln:product>cpe:/a:gnu:mailman:2.0.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0052</vuln:cve-id>
    <vuln:published-datetime>2006-03-31T06:06:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:37:22.740-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-03-31T13:51:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9475" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9475" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/17311" xml:lang="en">17311</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=358892" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=358892</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntulinux.org/support/documentation/usn/usn-267-1" xml:lang="en">USN-267-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2006-0486.html" xml:lang="en">RHSA-2006:0486</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/24367" xml:lang="en">24367</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2006_08_sr.html" xml:lang="en">SUSE-SR:2006:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:061" xml:lang="en">MDKSA-2006:061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1027" xml:lang="en">DSA-1027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015851" xml:lang="en">1015851</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20782" xml:lang="en">20782</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20624" xml:lang="en">20624</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19571" xml:lang="en">19571</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19545" xml:lang="en">19545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19522" xml:lang="en">19522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc" xml:lang="en">20060602-01-U</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9475" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9475" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python's library email module 2.5, allows remote attackers to cause a denial of service (mailing list delivery failure) via a multipart MIME message with a single part that has two blank lines between the first boundary and the end boundary.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0053">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:tony_cook:imager:0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:tony_cook:imager:0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:tony_cook:imager:0.43"/>
        <cpe-lang:fact-ref name="cpe:/a:tony_cook:imager:0.44_1"/>
        <cpe-lang:fact-ref name="cpe:/a:tony_cook:imager:0.45"/>
        <cpe-lang:fact-ref name="cpe:/a:tony_cook:imager:0.45_2"/>
        <cpe-lang:fact-ref name="cpe:/a:tony_cook:imager:0.47"/>
        <cpe-lang:fact-ref name="cpe:/a:tony_cook:imager:0.48"/>
        <cpe-lang:fact-ref name="cpe:/a:tony_cook:imager:0.49"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tony_cook:imager:0.42</vuln:product>
      <vuln:product>cpe:/a:tony_cook:imager:0.45_2</vuln:product>
      <vuln:product>cpe:/a:tony_cook:imager:0.43</vuln:product>
      <vuln:product>cpe:/a:tony_cook:imager:0.47</vuln:product>
      <vuln:product>cpe:/a:tony_cook:imager:0.41</vuln:product>
      <vuln:product>cpe:/a:tony_cook:imager:0.48</vuln:product>
      <vuln:product>cpe:/a:tony_cook:imager:0.45</vuln:product>
      <vuln:product>cpe:/a:tony_cook:imager:0.49</vuln:product>
      <vuln:product>cpe:/a:tony_cook:imager:0.44_1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0053</vuln:cve-id>
    <vuln:published-datetime>2006-04-10T14:06:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-05-06T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-04-10T14:24:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/17415" xml:lang="en">17415</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1028" xml:lang="en">DSA-1028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19577" xml:lang="en">19577</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19575" xml:lang="en">19575</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/25717" xml:lang="en">imager-jpeg-tga-dos(25717)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1294" xml:lang="en">ADV-2006-1294</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://rt.cpan.org/Public/Bug/Display.html?id=18397" xml:lang="en">http://rt.cpan.org/Public/Bug/Display.html?id=18397</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=359661" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=359661</vuln:reference>
    </vuln:references>
    <vuln:summary>Imager (libimager-perl) before 0.50 allows user-assisted attackers to cause a denial of service (segmentation fault) by writing a 2- or 4-channel JPEG image (or a 2-channel TGA image) to a scalar, which triggers a NULL pointer dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0054">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.0:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.0:stable"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:6.0:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:6.0:release</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0054</vuln:cve-id>
    <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:14.483-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T07:57:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16209" xml:lang="en">16209</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18378" xml:lang="en">18378</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:04.ipfw.asc" xml:lang="en">FreeBSD-SA-06:04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24073" xml:lang="en">ipfw-icmp-fragment-dos(24073)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22319" xml:lang="en">22319</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015477" xml:lang="en">1015477</vuln:reference>
    </vuln:references>
    <vuln:summary>The ipfw firewall in FreeBSD 6.0-RELEASE allows remote attackers to cause a denial of service (firewall crash) via ICMP IP fragments that match a reset, reject or unreach action, which leads to an access of an uninitialized pointer.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0055">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.10:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.10:release_p8"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.10:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.11:release_p3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.11:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:4.11:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0:release_p14"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:release_p5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.1:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.2.1:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.3:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.3:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.3:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.4:pre-release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.4:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.4:releng"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.0:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.0:stable"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.10:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0:release_p14</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1:release_p5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.2.1:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.11:release_p3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.3:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.11:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.3:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0:alpha</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.4:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.10:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:6.0:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.3:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:6.0:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.11:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.4:pre-release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.1:alpha</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.10</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.4:releng</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:4.10:release_p8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.2.1:releng</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0055</vuln:cve-id>
    <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:14.637-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T08:01:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16207" xml:lang="en">16207</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18404" xml:lang="en">18404</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:02.ee.asc" xml:lang="en">FreeBSD-SA-06:02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24074" xml:lang="en">ee-ispell-op-symlink(24074)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22320" xml:lang="en">22320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015469" xml:lang="en">1015469</vuln:reference>
    </vuln:references>
    <vuln:summary>The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0056">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pam-mysql:pam-mysql:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pam-mysql:pam-mysql:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pam-mysql:pam-mysql:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:pam-mysql:pam-mysql:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:pam-mysql:pam-mysql:0.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:pam-mysql:pam-mysql:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:pam-mysql:pam-mysql:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:pam-mysql:pam-mysql:0.7_pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:pam-mysql:pam-mysql:0.7_pre2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pam-mysql:pam-mysql:0.6</vuln:product>
      <vuln:product>cpe:/a:pam-mysql:pam-mysql:0.4</vuln:product>
      <vuln:product>cpe:/a:pam-mysql:pam-mysql:0.7_pre1</vuln:product>
      <vuln:product>cpe:/a:pam-mysql:pam-mysql:0.5</vuln:product>
      <vuln:product>cpe:/a:pam-mysql:pam-mysql:0.7_pre2</vuln:product>
      <vuln:product>cpe:/a:pam-mysql:pam-mysql:0.3</vuln:product>
      <vuln:product>cpe:/a:pam-mysql:pam-mysql:0.4.7</vuln:product>
      <vuln:product>cpe:/a:pam-mysql:pam-mysql:0.2</vuln:product>
      <vuln:product>cpe:/a:pam-mysql:pam-mysql:0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0056</vuln:cve-id>
    <vuln:published-datetime>2006-02-13T06:06:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:14.283-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-02-13T08:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/693909" xml:lang="en">VU#693909</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16564" xml:lang="en">16564</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015603" xml:lang="en">1015603</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18598" xml:lang="en">18598</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0490" xml:lang="en">ADV-2006-0490</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22995" xml:lang="en">22995</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22994" xml:lang="en">22994</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200606-18.xml" xml:lang="en">GLSA-200606-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/forum/forum.php?forum_id=499394" xml:lang="en">http://sourceforge.net/forum/forum.php?forum_id=499394</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20690" xml:lang="en">20690</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://jvn.jp/cert/JVNVU%23693909/index.html" xml:lang="en">http://jvn.jp/cert/JVNVU%23693909/index.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Double free vulnerability in the authentication and authentication token alteration code in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted passwords, which lead to a double free of a pointer that was created by the pam_get_item function.  NOTE: this issue only occurs in certain configurations in which there are multiple PAM modules, PAM-MySQL is not evaluated first, and there are no requisite modules before PAM-MySQL.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0057">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.01:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6:windows_server_2003_sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:6:windows_server_2003_sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.01:sp4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0057</vuln:cve-id>
    <vuln:published-datetime>2006-01-27T17:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:15.030-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-30T08:35:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/998297" xml:lang="en">VU#998297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms05-054.mspx" xml:lang="en">http://www.microsoft.com/technet/security/bulletin/ms05-054.mspx</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24379" xml:lang="en">ie-activex-killbit-bypass(24379)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16409" xml:lang="en">16409</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/23657" xml:lang="en">23657</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to bypass the Kill bit settings for dangerous ActiveX controls via unknown vectors involving crafted HTML, which can expose the browser to attacks that would otherwise be prevented by the Kill bit setting. NOTE: CERT/CC claims that MS05-054 fixes this issue, but it is not described in MS05-054.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0058">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.13.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.13.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.13.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.13.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.13.4"/>
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.13.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sendmail:sendmail:8.13.1</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.13.5</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.13.4</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.13.3</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.13.0</vuln:product>
      <vuln:product>cpe:/a:sendmail:sendmail:8.13.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0058</vuln:cve-id>
    <vuln:published-datetime>2006-03-22T15:06:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:14.517-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-03-23T13:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11074" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11074" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1689" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1689" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA06-081A.html" xml:lang="en">TA06-081A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/834865" xml:lang="en">VU#834865</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2006-0265.html" xml:lang="en">RHSA-2006:0265</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2006-0264.html" xml:lang="en">RHSA-2006:0264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/2490" xml:lang="en">ADV-2006-2490</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/2189" xml:lang="en">ADV-2006-2189</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1529" xml:lang="en">ADV-2006-1529</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1157" xml:lang="en">ADV-2006-1157</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1139" xml:lang="en">ADV-2006-1139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1072" xml:lang="en">ADV-2006-1072</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1068" xml:lang="en">ADV-2006-1068</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1051" xml:lang="en">ADV-2006-1051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1049" xml:lang="en">ADV-2006-1049</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.sendmail.com/company/advisory/index.shtml" xml:lang="en">http://www.sendmail.com/company/advisory/index.shtml</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/428536/100/0/threaded" xml:lang="en">20060322 sendmail vuln advisories (CVE-2006-0058)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.007-sendmail.html" xml:lang="en">OpenPKG-SA-2006.007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/216.html" xml:lang="en">20060322 Sendmail Remote Signal Handling Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200603-21.xml" xml:lang="en">GLSA-200603-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1015" xml:lang="en">DSA-1015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200494-1" xml:lang="en">200494</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19367" xml:lang="en">19367</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19363" xml:lang="en">19363</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19342" xml:lang="en">19342</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635" xml:lang="en">HPSBTU02116</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00629555" xml:lang="en">HPSBUX02108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24584" xml:lang="en">smtp-timeout-bo(24584)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=2751" xml:lang="en">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=2751</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688" xml:lang="en">http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/17192" xml:lang="en">17192</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/428656/100/0/threaded" xml:lang="en">FLSA:186277</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00018.html" xml:lang="en">FEDORA-2006-193</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00017.html" xml:lang="en">FEDORA-2006-194</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/24037" xml:lang="en">24037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENBSD</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata38.html#sendmail" xml:lang="en">[3.8] 006: SECURITY FIX: March 25, 2006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2006_17_sendmail.html" xml:lang="en">SUSE-SA:2006:017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:058" xml:lang="en">MDKSA-2006:058</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.f-secure.com/security/fsc-2006-2.shtml" xml:lang="en">http://www.f-secure.com/security/fsc-2006-2.shtml</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/q-151.shtml" xml:lang="en">Q-151</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY82994&amp;apar=only" xml:lang="en">IY82994</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY82993&amp;apar=only" xml:lang="en">IY82993</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY82992&amp;apar=only" xml:lang="en">IY82992</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102324-1" xml:lang="en">102324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102262-1" xml:lang="en">102262</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.619600" xml:lang="en">SSA:2006-081-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015801" xml:lang="en">1015801</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/743" xml:lang="en">743</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/612" xml:lang="en">612</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20723" xml:lang="en">20723</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20243" xml:lang="en">20243</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19774" xml:lang="en">19774</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19676" xml:lang="en">19676</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19533" xml:lang="en">19533</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19532" xml:lang="en">19532</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19466" xml:lang="en">19466</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19450" xml:lang="en">19450</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19407" xml:lang="en">19407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19404" xml:lang="en">19404</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19394" xml:lang="en">19394</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19368" xml:lang="en">19368</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19361" xml:lang="en">19361</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19360" xml:lang="en">19360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19356" xml:lang="en">19356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19349" xml:lang="en">19349</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19346" xml:lang="en">19346</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19345" xml:lang="en">19345</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635" xml:lang="en">HPSBTU02116</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00629555" xml:lang="en">HPSBUX02108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U" xml:lang="en">20060401-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20060302-01-P" xml:lang="en">20060302-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SCO</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.24/SCOSA-2006.24.txt" xml:lang="en">SCOSA-2006.24</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-010.txt.asc" xml:lang="en">NetBSD-SA2006-010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:13.sendmail.asc" xml:lang="en">FreeBSD-SA-06:13</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1689" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1689" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11074" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11074" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0059">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:livedata:iccp_server:5.00.045"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:livedata:iccp_server:5.00.045</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0059</vuln:cve-id>
    <vuln:published-datetime>2006-05-19T15:02:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:14.673-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-05-19T15:08:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/190617" xml:lang="en">VU#190617</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1830" xml:lang="en">ADV-2006-1830</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/JGEI-6MMS9T" xml:lang="en">http://www.kb.cert.org/vuls/id/JGEI-6MMS9T</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/26490" xml:lang="en">livedata-iccp-rfc1006-bo(26490)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/18010" xml:lang="en">18010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitalbond.com/SCADA_Blog/2006/05/us-cert-livedata-iccp-vulnerability.html" xml:lang="en">http://www.digitalbond.com/SCADA_Blog/2006/05/us-cert-livedata-iccp-vulnerability.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1016113" xml:lang="en">1016113</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20146" xml:lang="en">20146</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in the ISO Transport Service over TCP (RFC 1006) implementation of LiveData ICCP Server before 5.00.035 allows remote attackers to cause a denial of service or execute arbitrary code via malformed packets.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0063">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpbb_group:phpbb:2.0.19"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpbb_group:phpbb:2.0.19</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0063</vuln:cve-id>
    <vuln:published-datetime>2006-01-05T14:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T08:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0051" xml:lang="en">ADV-2006-0051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22672" xml:lang="en">22672</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/313" xml:lang="en">313</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/313" xml:lang="en">http://securityreason.com/securityalert/313</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SREASONRES</vuln:source>
      <vuln:reference href="http://securityreason.com/achievement_securityalert/30" xml:lang="en">20060105 phpBB 2.0.19 XSS</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in phpBB 2.0.19, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary web script or HTML via a permitted HTML tag with ' (single quote) characters and active attributes such as onmouseover, a variant of CVE-2005-4357.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0064">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:devellion:cubecart"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:devellion:cubecart</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0064</vuln:cve-id>
    <vuln:published-datetime>2006-01-03T17:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-08-23T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-03T17:39:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0016" xml:lang="en">ADV-2006-0016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/1398" xml:lang="en">1398</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitrary PHP code via a URL in the glob[rootDir] parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0065">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:vego:vego_web_forum:1.26"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vego:vego_web_forum:1.26</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0065</vuln:cve-id>
    <vuln:published-datetime>2006-01-03T17:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:14.907-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-04T08:50:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0003" xml:lang="en">ADV-2006-0003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420661/100/0/threaded" xml:lang="en">20060101 [eVuln] VEGO Web Forum SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18273" xml:lang="en">18273</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/1/summary.html" xml:lang="en">http://evuln.com/vulns/1/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16107" xml:lang="en">16107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22140" xml:lang="en">22140</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/315" xml:lang="en">315</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in (1) functions.php, (2) functions_update.php, and (3) functions_display.php in VEGO Web Forum 1.26 and earlier allows remote attackers to execute arbitrary SQL commands via the theme_id parameter in index.php.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0066">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpjournaler:phpjournaler:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpjournaler:phpjournaler:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0066</vuln:cve-id>
    <vuln:published-datetime>2006-01-03T17:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:15.017-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-04T08:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0006" xml:lang="en">ADV-2006-0006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16111" xml:lang="en">16111</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420666/100/0/threaded" xml:lang="en">20060101 [eVuln] PHPjournaler SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22149" xml:lang="en">22149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18265" xml:lang="en">18265</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/9/summary.html" xml:lang="en">http://evuln.com/vulns/9/summary.html</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in index.php in PHPjournaler 1.0 allows remote attackers to execute arbitrary SQL commands via the readold parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0067">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:vego:vego_links_builder:2.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vego:vego_links_builder:2.00</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0067</vuln:cve-id>
    <vuln:published-datetime>2006-01-03T17:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:15.097-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-04T08:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0004" xml:lang="en">ADV-2006-0004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18272" xml:lang="en">18272</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/2/summary.html" xml:lang="en">http://evuln.com/vulns/2/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16108" xml:lang="en">16108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22139" xml:lang="en">22139</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in login.php in VEGO Links Builder 2.00 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0068">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:primo_place:primo_cart:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:primo_place:primo_cart:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0068</vuln:cve-id>
    <vuln:published-datetime>2006-01-03T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:15.173-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-04T08:47:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0008" xml:lang="en">ADV-2006-0008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18264" xml:lang="en">18264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16125" xml:lang="en">16125</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22147" xml:lang="en">22147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22146" xml:lang="en">22146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://pridels0.blogspot.com/2006/01/primo-cart-sql-inj.html" xml:lang="en">http://pridels0.blogspot.com/2006/01/primo-cart-sql-inj.html</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in Primo Cart 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) q parameter to search.php and (2) email parameter to user.php.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0069">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:chipmunk_scripts:chipmunk_guestbook:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:chipmunk_scripts:chipmunk_guestbook:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0069</vuln:cve-id>
    <vuln:published-datetime>2006-01-03T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:16.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-04T08:48:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/19087" xml:lang="en">19087</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16112" xml:lang="en">16112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420667/100/0/threaded" xml:lang="en">20060101 [eVuln] Chipmunk Guestbook XSS Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18270" xml:lang="en">18270</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/4/summary.html" xml:lang="en">http://evuln.com/vulns/4/summary.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in addentry.php in Chipmunk Guestbook 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the homepage parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0070">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:drupal:drupal:4.5.6</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0070</vuln:cve-id>
    <vuln:published-datetime>2006-01-03T19:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:16.497-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-04T08:28:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420683/100/0/threaded" xml:lang="en">20060103 Re: Drupal all versiyon xss cehennem.org</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/420671/100/0/threaded" xml:lang="en">20060102 Drupal all versiyon xss cehennem.org</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  Drupal allows remote attackers to conduct cross-site scripting (XSS) attacks via an IMG tag with an unusual encoded Javascript function name, as demonstrated using variations of the alert() function.  NOTE: a followup by the vendor suggests that the issue does not exist in 4.5.6 or 4.6.4 when "Filtered HTML" is enabled, and since "Full HTML" would not filter HTML by design, perhaps this should not be included in CVE.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0071">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gentoo:app-crypt_pinentry:0.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gentoo:app-crypt_pinentry:0.7.2:r1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:gentoo:linux</vuln:product>
      <vuln:product>cpe:/a:gentoo:app-crypt_pinentry:0.7.2:r1</vuln:product>
      <vuln:product>cpe:/a:gentoo:app-crypt_pinentry:0.7.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0071</vuln:cve-id>
    <vuln:published-datetime>2006-01-03T19:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:16.653-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-04T08:39:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16120" xml:lang="en">16120</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200601-01.xml" xml:lang="en">GLSA-200601-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22211" xml:lang="en">22211</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18284" xml:lang="en">18284</vuln:reference>
    </vuln:references>
    <vuln:summary>The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitrary files as gid 0.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0072">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.6a"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sco:openserver:5.0.5</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.3</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.6</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.7</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.1</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.6a</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.2</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0072</vuln:cve-id>
    <vuln:published-datetime>2006-01-03T19:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:16.797-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-04T08:42:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16122" xml:lang="en">16122</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/420677" xml:lang="en">20060102 SCO Openserver 5.0.x exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://downloads.securityfocus.com/vulnerabilities/exploits/Openserver_bof.c" xml:lang="en">http://downloads.securityfocus.com/vulnerabilities/exploits/Openserver_bof.c</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in termsh on SCO OpenServer 5.0.7 allows remote attackers to execute arbitrary code via a long -o command line argument.  NOTE: this is probably a different vulnerability than CVE-2005-0351 since it involves a distinct attack vector.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0073">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:discusware:discus_freeware:3.10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:discusware:discus_professional:3.10.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:discusware:discus_professional:3.10.4</vuln:product>
      <vuln:product>cpe:/a:discusware:discus_freeware:3.10.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0073</vuln:cve-id>
    <vuln:published-datetime>2006-01-03T19:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:16.967-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-04T08:44:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16119" xml:lang="en">16119</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22153" xml:lang="en">22153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18283" xml:lang="en">18283</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in DiscusWare Discus Freeware 3.10.5 and Professional 3.10.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a URL, which is not properly sanitized from the resulting error message.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0074">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:jevontech:phpenpals:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jevontech:phpenpals:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0074</vuln:cve-id>
    <vuln:published-datetime>2006-01-03T20:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-08-05T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-04T08:20:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0005" xml:lang="en">ADV-2006-0005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16109" xml:lang="en">16109</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420690/100/0/threaded" xml:lang="en">20060101 [eVuln] PHPenpals SQL Injection Vulnerabilit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22150" xml:lang="en">22150</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/8706" xml:lang="en">8706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18269" xml:lang="en">18269</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/5/summary.html" xml:lang="en">http://evuln.com/vulns/5/summary.html</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter.  NOTE: it was later reported that 1.1 and earlier are affected.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0075">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:phpbook:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:phpbook:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:phpbook:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:phpbook:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:phpbook:1.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:phpbook:1.3.2</vuln:product>
      <vuln:product>cpe:/a:gnu:phpbook:1.2</vuln:product>
      <vuln:product>cpe:/a:gnu:phpbook:1.3</vuln:product>
      <vuln:product>cpe:/a:gnu:phpbook:1.0</vuln:product>
      <vuln:product>cpe:/a:gnu:phpbook:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0075</vuln:cve-id>
    <vuln:published-datetime>2006-01-03T20:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:15.703-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-04T08:22:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16106" xml:lang="en">16106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420698/100/0/threaded" xml:lang="en">20060101 [eVuln] phpBook PHP Code Execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/6/summary.html" xml:lang="en">http://evuln.com/vulns/6/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0002" xml:lang="en">ADV-2006-0002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18268" xml:lang="en">18268</vuln:reference>
    </vuln:references>
    <vuln:summary>Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (mail variable) in a new message, which is written to a PHP file.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0076">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oaboard:oaboard:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oaboard:oaboard:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0076</vuln:cve-id>
    <vuln:published-datetime>2006-01-03T20:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-04T08:23:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16105" xml:lang="en">16105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/435859/100/0/threaded" xml:lang="en">20060531 Re: OaBoard 1.0 Remote File inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/435371/100/0/threaded" xml:lang="en">20060530 OaBoard 1.0 Remote File inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420676/100/0/threaded" xml:lang="en">20060101 [eVuln] oaBoard PHP Code Execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1016211" xml:lang="en">1016211</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/3/summary.html" xml:lang="en">http://evuln.com/vulns/3/summary.html</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0077">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:richard_dawe:file_extattr:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:richard_dawe:file_extattr:0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:richard_dawe:file_extattr:0.1</vuln:product>
      <vuln:product>cpe:/a:richard_dawe:file_extattr:0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0077</vuln:cve-id>
    <vuln:published-datetime>2006-01-03T20:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:15.830-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-04T08:26:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16118" xml:lang="en">16118</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=382199&amp;group_id=153116" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=382199&amp;group_id=153116</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18253" xml:lang="en">18253</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0013" xml:lang="en">ADV-2006-0013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22160" xml:lang="en">22160</vuln:reference>
    </vuln:references>
    <vuln:summary>Off-by-one error in the getfattr function in File::ExtAttr before 0.03 allows attackers to trigger a buffer overflow via unspecified attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0078">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:haddad_said:b-net_software:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:haddad_said:b-net_software:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0078</vuln:cve-id>
    <vuln:published-datetime>2006-01-04T01:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:15.893-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-04T08:08:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0018" xml:lang="en">ADV-2006-0018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16114" xml:lang="en">16114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420673/100/0/threaded" xml:lang="en">20060102 [eVuln] B-net Software Multiple XSS Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18271" xml:lang="en">18271</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/10/summary.html" xml:lang="en">http://evuln.com/vulns/10/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/444320/100/0/threaded" xml:lang="en">20060825 Re: [eVuln] B-net Software Multiple XSS Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22191" xml:lang="en">22191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22190" xml:lang="en">22190</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=442067&amp;group_id=117067" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=442067&amp;group_id=117067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/316" xml:lang="en">316</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in B-net Software 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) shout variables to (a) shout.php, or the (3) title and (4) message variables to (b) guestbook.php.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0079">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:scoznet:scozbook:1.1_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:scoznet:scozbook:1.1_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0079</vuln:cve-id>
    <vuln:published-datetime>2006-01-04T01:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:15.987-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-04T08:11:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0027" xml:lang="en">ADV-2006-0027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16115" xml:lang="en">16115</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420675/100/0/threaded" xml:lang="en">20060102 [eVuln] ScozBook "adminname" Authentication Bypass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/11/summary.html" xml:lang="en">http://evuln.com/vulns/11/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22221" xml:lang="en">22221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/318" xml:lang="en">318</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/8476" xml:lang="en">8476</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in auth.php in ScozNet ScozBook BETA 1.1 allows remote attackers to execute arbitrary SQL commands via the username field (adminname variable).</vuln:summary>
  </entry>
  <entry id="CVE-2006-0080">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jelsoft:vbulletin:3.5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0080</vuln:cve-id>
    <vuln:published-datetime>2006-01-04T01:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:18.313-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-04T08:13:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0033" xml:lang="en">ADV-2006-0033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16116" xml:lang="en">16116</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421310/100/0/threaded" xml:lang="en">20060108 Html_Injection in vBulletin 3.5.2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420663/100/0/threaded" xml:lang="en">20060101 [KAPDA::#19] - Html Injection in vBulletin 3.5.2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22220" xml:lang="en">22220</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22210" xml:lang="en">22210</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18299" xml:lang="en">18299</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://kapda.ir/advisory-177.html" xml:lang="en">http://kapda.ir/advisory-177.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in vBulletin 3.5.2, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the title of an event, which is not properly filtered by (1) calendar.php and (2) reminder.php.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0081">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:intel:graphics_accelerator_driver:6.14.10.4308"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:intel:graphics_accelerator_driver:6.14.10.4308</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0081</vuln:cve-id>
    <vuln:published-datetime>2006-01-04T01:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-04T08:17:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0017" xml:lang="en">ADV-2006-0017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16127" xml:lang="en">16127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22196" xml:lang="en">22196</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18286" xml:lang="en">18286</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0029.html" xml:lang="en">20060103 Re: Buffer Overflow vulnerability in Windows Display Manager [Suspected]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0029.html" xml:lang="en">20060103 Re: Buffer Overflow vulnerability in Windows Display Manager [Suspected]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0003.html" xml:lang="en">20060102 Buffer Overflow vulnerability in Windows Display Manager [Suspected]</vuln:reference>
    </vuln:references>
    <vuln:summary>ialmnt5.sys in the ialmrnt5 display driver in Intel Graphics Accelerator Driver 6.14.10.4308 allows attackers to cause a denial of service (crash or screen resolution change) via a long text field, as demonstrated using a long window title.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0082">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0082</vuln:cve-id>
    <vuln:published-datetime>2006-01-04T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T09:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10717" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10717" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-134"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/12717" xml:lang="en">12717</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200602-13.xml" xml:lang="en">GLSA-200602-13.xml</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200602-06.xml" xml:lang="en">GLSA-200602-06</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.341682" xml:lang="en">SSA:2006-045-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19183" xml:lang="en">19183</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19030" xml:lang="en">19030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18851" xml:lang="en">18851</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18607" xml:lang="en">18607</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc" xml:lang="en">20060301-01-U</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-389" xml:lang="en">https://issues.rpath.com/browse/RPL-389</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0412" xml:lang="en">ADV-2008-0412</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-246-1" xml:lang="en">USN-246-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/452718/100/100/threaded" xml:lang="en">20061127 rPSA-2006-0218-1 ImageMagick</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2006_06_sr.html" xml:lang="en">SUSE-SR:2006:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:024" xml:lang="en">MDKSA-2006:024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1213" xml:lang="en">DSA-1213</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-231321-1" xml:lang="en">231321</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015623" xml:lang="en">1015623</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/500" xml:lang="en">500</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28800" xml:lang="en">28800</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23090" xml:lang="en">23090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/22998" xml:lang="en">22998</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19408" xml:lang="en">19408</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18871" xml:lang="en">18871</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18261" xml:lang="en">18261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2006-0178.html" xml:lang="en">RHSA-2006:0178</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10717" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10717" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0083">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:stefan_frings:sms_server_tools"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:stefan_frings:sms_server_tools</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0083</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T15:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:18.467-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-09T15:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18357" xml:lang="en">18357</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24034" xml:lang="en">smstools-logging-format-string(24034)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16188" xml:lang="en">16188</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22287" xml:lang="en">22287</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2005/dsa-930" xml:lang="en">DSA-930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18343" xml:lang="en">18343</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in the logging code of SMS Server Tools (smstools) 1.14.8 and earlier allows local users to execute arbitrary code via unspecified attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0084">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rasmp:rasmp:2.0.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rasmp:rasmp:2.0.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0084</vuln:cve-id>
    <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:18.643-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-05T08:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0030" xml:lang="en">ADV-2006-0030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16138" xml:lang="en">16138</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22198" xml:lang="en">22198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18292" xml:lang="en">18292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/13/summary.html" xml:lang="en">http://evuln.com/vulns/13/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015432" xml:lang="en">1015432</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2006-January/000486.html" xml:lang="en">20060116 vendor ack/fix: 22198: raSMP index.php User-Agent Field XSS (fwd)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting vulnerability in index.php in raSMP 2.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the $_SERVER[HTTP_USER_AGENT] variable (User-Agent header).</vuln:summary>
  </entry>
  <entry id="CVE-2006-0085">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:nkads:nkads:1.0alfa2"/>
        <cpe-lang:fact-ref name="cpe:/a:nkads:nkads:1.0alfa3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nkads:nkads:1.0alfa3</vuln:product>
      <vuln:product>cpe:/a:nkads:nkads:1.0alfa2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0085</vuln:cve-id>
    <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:18.720-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T08:55:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0040" xml:lang="en">ADV-2006-0040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.soulblack.com.ar/repo/papers/advisory/nkads_advisory.txt" xml:lang="en">http://www.soulblack.com.ar/repo/papers/advisory/nkads_advisory.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18302" xml:lang="en">18302</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22206" xml:lang="en">22206</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in Nkads 1.0 alfa 3 allows remote attackers to execute arbitrary SQL commands via the (1) usuario_nkads_admin or (2) password_nkads_admin parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0086">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:next_generation_image_gallery:next_generation_image_gallery:0.0.1_lite"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:next_generation_image_gallery:next_generation_image_gallery:0.0.1_lite</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0086</vuln:cve-id>
    <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:18.813-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T08:58:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0037" xml:lang="en">ADV-2006-0037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18309" xml:lang="en">18309</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22202" xml:lang="en">22202</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://osvdb.org/ref/22/22202-nextgen.txt" xml:lang="en">http://osvdb.org/ref/22/22202-nextgen.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting vulnerability in index.php in Next Generation Image Gallery 0.0.1 Lite Edition allows remote attackers to inject arbitrary web script or HTML via the page parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0087">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:lizard_cart:lizard_cart_cms:1.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lizard_cart:lizard_cart_cms:1.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0087</vuln:cve-id>
    <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:18.907-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T08:59:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0029" xml:lang="en">ADV-2006-0029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16140" xml:lang="en">16140</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420772/100/0/threaded" xml:lang="en">20060104 [eVuln] Lizard Cart CMS SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18297" xml:lang="en">18297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22200" xml:lang="en">22200</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22199" xml:lang="en">22199</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.evuln.com/vulns/12/summary.html" xml:lang="en">http://www.evuln.com/vulns/12/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015435" xml:lang="en">1015435</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/314" xml:lang="en">314</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in (1) pages.php and (2) detail.php in Lizard Cart CMS 1.04 allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0088">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:intouch:intouch:0.5.1_alpha"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:intouch:intouch:0.5.1_alpha</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0088</vuln:cve-id>
    <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:19.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T09:02:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0026" xml:lang="en">ADV-2006-0026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16110" xml:lang="en">16110</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420672/100/0/threaded" xml:lang="en">20060101 [eVuln] inTouch Authentication Bypass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/8/summary.html" xml:lang="en">http://evuln.com/vulns/8/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/23954" xml:lang="en">intouch-intouch-sql-injection(23954)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22382" xml:lang="en">22382</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in intouch.lib.php in inTouch 0.5.1 Alpha allows remote attackers to execute arbitrary SQL commands via the user parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0089">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:esri:arcpad:7.0.0.156"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:esri:arcpad:7.0.0.156</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0089</vuln:cve-id>
    <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:19.097-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T09:03:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0032" xml:lang="en">ADV-2006-0032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16136" xml:lang="en">16136</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://users.pandora.be/bratax/advisories/b007.html" xml:lang="en">http://users.pandora.be/bratax/advisories/b007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18294" xml:lang="en">18294</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22208" xml:lang="en">22208</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in ESRI ArcPad 7.0.0.156 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .amp file with a COORDSYS tag with a long string attribute.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0090">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:idv_directory_viewer:idv_directory_viewer:2005.1_b1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:idv_directory_viewer:idv_directory_viewer:2005.1_b1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0090</vuln:cve-id>
    <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:19.187-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T09:05:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=382593&amp;group_id=152499" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=382593&amp;group_id=152499</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0031" xml:lang="en">ADV-2006-0031</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18298" xml:lang="en">18298</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16137" xml:lang="en">16137</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in index.php in IDV Directory Viewer before 2005.1 allows remote attackers to view arbitrary directory contents via a .. (dot dot) in the dir parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0091">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:open-xchange:open-xchange:0.8.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:open-xchange:open-xchange:0.8.1.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0091</vuln:cve-id>
    <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:19.283-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T09:06:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0034" xml:lang="en">ADV-2006-0034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18285" xml:lang="en">18285</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113629092325679&amp;w=2" xml:lang="en">20060103 Open Xchange XSS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015431" xml:lang="en">1015431</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in webmail in Open-Xchange 0.8.1-6 and earlier, with "Inline HTML" enabled, allows remote attackers to inject arbitrary web script or HTML via e-mail attachments, which are rendered inline.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0092">
    <vuln:cve-id>CVE-2006-0092</vuln:cve-id>
    <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:55:26.397-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0992, CVE-2006-0158.  Reason: this candidate was intended for one issue, but a typo caused it to be associated with a Novell/Groupwise issue.  In addition, this issue was a duplicate of a SiteSuite issue that was also assigned CVE-2006-0158.  Notes: All CVE users should consult CVE-2006-0992 and CVE-2006-0158 to determine which ID is appropriate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0093">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ecardmax.com:atcard_me_php"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ecardmax.com:atcard_me_php</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0093</vuln:cve-id>
    <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:19.407-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T09:11:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0039" xml:lang="en">ADV-2006-0039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22203" xml:lang="en">22203</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18306" xml:lang="en">18306</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://osvdb.org/ref/22/22203-ecardmax.txt" xml:lang="en">http://osvdb.org/ref/22/22203-ecardmax.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in @Card ME PHP allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0094">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oaboard:oaboard:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oaboard:oaboard:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0094</vuln:cve-id>
    <vuln:published-datetime>2006-01-05T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-08-23T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T09:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0028" xml:lang="en">ADV-2006-0028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/17373" xml:lang="en">17373</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_stat parameter, a different vulnerability than CVE-2006-0076. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0095">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:2.6.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:2.6.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0095</vuln:cve-id>
    <vuln:published-datetime>2006-01-06T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:19.580-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T08:11:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11192" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11192" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113640535312572&amp;w=2" xml:lang="en">[linux-kernel] 20060104 [Patch 2.6] dm-crypt: zero key before freeing it</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0235" xml:lang="en">ADV-2006-0235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113641114812886&amp;w=2" xml:lang="en">[linux-kernel] 20060104 [Patch 2.6] dm-crypt: Zero key material before free to avoid information leak</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24189" xml:lang="en">kernel-dmcrypt-information-disclosure(24189)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntulinux.org/support/documentation/usn/usn-244-1" xml:lang="en">USN-244-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2006/0004" xml:lang="en">2006-0004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16301" xml:lang="en">16301</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/427981/100/0/threaded" xml:lang="en">FLSA:157459-4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2006-0132.html" xml:lang="en">RHSA-2006:0132</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00037.html" xml:lang="en">FEDORA-2006-102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22418" xml:lang="en">22418</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2006-05-31.html" xml:lang="en">SUSE-SA:2006:028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:040" xml:lang="en">MDKSA-2006:040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1017" xml:lang="en">DSA-1017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015740" xml:lang="en">1015740</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/388" xml:lang="en">388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20398" xml:lang="en">20398</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19374" xml:lang="en">19374</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19160" xml:lang="en">19160</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18774" xml:lang="en">18774</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18527" xml:lang="en">18527</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18487" xml:lang="en">18487</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11192" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11192" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>dm-crypt in Linux kernel 2.6.15 and earlier does not clear a structure before it is freed, which leads to a memory disclosure that could allow local users to obtain sensitive information about a cryptographic key.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0096">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.0:test9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.18:pre8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.19:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.21:pre7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23:pre9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.23_ow2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.24_ow1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.27:pre5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:2.6.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.24_ow1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23:pre9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:2.6.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23_ow2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18::x86</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.27:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.21:pre4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0:test5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.19:pre1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.18:pre2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0096</vuln:cve-id>
    <vuln:published-datetime>2006-01-06T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-20T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T08:13:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044" xml:lang="en">MDKSA-2006:044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntulinux.org/support/documentation/usn/usn-244-1" xml:lang="en">USN-244-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16304" xml:lang="en">16304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/git/?p=linux/kernel/git/tglx/history.git;a=commitdiff;h=0f1d4813a4a65296e1131f320a60741732bc068f" xml:lang="en">http://www.kernel.org/git/?p=linux/kernel/git/tglx/history.git;a=commitdiff;h=0f1d4813a4a65296e1131f320a60741732bc068f</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1017" xml:lang="en">DSA-1017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19374" xml:lang="en">19374</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18977" xml:lang="en">18977</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18527" xml:lang="en">18527</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://linux.bkbits.net:8080/linux-2.4/cset@1.1448.91.23?nav=index.html%7Csrc/%7Csrc/drivers%7Csrc/drivers/net%7Csrc/drivers/net/wan%7Crelated/drivers/net/wan/sdla.c" xml:lang="en">http://linux.bkbits.net:8080/linux-2.4/cset@1.1448.91.23?nav=index.html|src/|src/drivers|src/drivers/net|src/drivers/net/wan|related/drivers/net/wan/sdla.c</vuln:reference>
    </vuln:references>
    <vuln:summary>wan/sdla.c in Linux kernel 2.6.x before 2.6.11 and 2.4.x before 2.4.29 does not require the CAP_SYS_RAWIO privilege for an SDLA firmware upgrade, with unknown impact and local attack vectors.  NOTE: further investigation suggests that this issue requires root privileges to exploit, since it is protected by CAP_NET_ADMIN; thus it might not be a vulnerability, although capabilities provide finer distinctions between privilege levels.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0097">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.4.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0097</vuln:cve-id>
    <vuln:published-datetime>2006-01-06T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-08-01T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T08:17:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0046" xml:lang="en">ADV-2006-0046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16145" xml:lang="en">16145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420986/100/0/threaded" xml:lang="en">20060105 Windows PHP 4.x </vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/ChangeLog-4.php#4.4.3" xml:lang="en">http://www.php.net/ChangeLog-4.php#4.4.3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22232" xml:lang="en">22232</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18275" xml:lang="en">18275</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041013.html" xml:lang="en">20060105 Windows PHP 4.x </vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0274.html" xml:lang="en">20060108 RE: Windows PHP 4.x </vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execute arbitrary code via a long (1) arg_host or (2) arg_unix_socket argument, as demonstrated by a long named pipe variable in the host argument to the mysql_connect function.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0098">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.7"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:openbsd:openbsd:3.8</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0098</vuln:cve-id>
    <vuln:published-datetime>2006-01-06T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:21.280-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T08:21:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16144" xml:lang="en">16144</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>OPENBSD</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata37.html#fd" xml:lang="en">[3.7] 20060105 008: SECURITY FIX: January 5, 2006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18296" xml:lang="en">18296</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/008_fd.patch" xml:lang="en">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/008_fd.patch</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22231" xml:lang="en">22231</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015437" xml:lang="en">1015437</vuln:reference>
    </vuln:references>
    <vuln:summary>The dupfdopen function in sys/kern/kern_descrip.c in OpenBSD 3.7 and 3.8 allows local users to re-open arbitrary files by using setuid programs to access file descriptors using /dev/fd/.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0099">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:valdersoft:valdersoft_shopping_cart:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:valdersoft:valdersoft_shopping_cart:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0099</vuln:cve-id>
    <vuln:published-datetime>2006-01-06T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:55:27.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T08:27:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16126" xml:lang="en">16126</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://downloads.securityfocus.com/vulnerabilities/exploits/cijfer-vscxpl.pl" xml:lang="en">http://downloads.securityfocus.com/vulnerabilities/exploits/cijfer-vscxpl.pl</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/1401" xml:lang="en">1401</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/templates/categories/ PHP scripts in Valdersoft Shopping Cart 3.0 allows remote attackers to execute arbitrary code via a URL in the catalogDocumentRoot parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0100">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:nicosw:nicoftp:3.0.1.19"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nicosw:nicoftp:3.0.1.19</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0100</vuln:cve-id>
    <vuln:published-datetime>2006-01-06T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:21.577-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T08:30:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420670/100/0/threaded" xml:lang="en">20060102 NicoFTP Stack Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/317" xml:lang="en">317</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in NicoFTP 3.0.1.19 and earlier might allow local users to execute arbitrary code via a long string in the "Name of site" field of an FTP account.  NOTE: because this program executes with the privileges of the invoking user, and because remote programs do not normally have the ability to create or modify FTP accounts in this program, there may not be a typical attack vector for the issue that crosses privilege boundaries.  Therefore this may not be a vulnerability.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0101">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sblog:sblog:0.7.1_build2005-12-02_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sblog:sblog:0.7.1_build2005-12-02_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0101</vuln:cve-id>
    <vuln:discovered-datetime>2006-01-06T00:00:00.000-05:00</vuln:discovered-datetime>
    <vuln:published-datetime>2006-01-06T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-13T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T08:31:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/23979" xml:lang="en">sblog-multiple-scripts-xss(23979)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0041" xml:lang="en">ADV-2006-0041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22374" xml:lang="en">22374</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22373" xml:lang="en">22373</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://osvdb.org/ref/22/22373-sblog.txt" xml:lang="en">http://osvdb.org/ref/22/22373-sblog.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in sBLOG 0.7.1 Beta 20051202 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p and (2) keyword parameters in (a) index.php and (b) search.php.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0102">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.46"/>
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.47"/>
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.48"/>
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.49"/>
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.499"/>
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.6</vuln:product>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.499</vuln:product>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.46</vuln:product>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.49</vuln:product>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.48</vuln:product>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.5</vuln:product>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.47</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0102</vuln:cve-id>
    <vuln:published-datetime>2006-01-06T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:20.187-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T08:36:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0054" xml:lang="en">ADV-2006-0054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded" xml:lang="en">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22256" xml:lang="en">22256</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015436" xml:lang="en">1015436</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18293" xml:lang="en">18293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/14/summary.html" xml:lang="en">http://evuln.com/vulns/14/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/320" xml:lang="en">320</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in TinyPHPForum (TPF) 3.6 and earlier allows remote attackers to inject arbitrary web script via a javascript: scheme in an "[a]" bbcode tag, possibly the txt parameter to action.php.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0103">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.46"/>
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.47"/>
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.48"/>
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.49"/>
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.499"/>
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.6</vuln:product>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.499</vuln:product>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.46</vuln:product>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.49</vuln:product>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.48</vuln:product>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.5</vuln:product>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.47</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0103</vuln:cve-id>
    <vuln:published-datetime>2006-01-06T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T08:47:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24016" xml:lang="en">tinyphpforum-users-information-disclosure(24016)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0054" xml:lang="en">ADV-2006-0054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/431133/100/0/threaded" xml:lang="en">20060417 Tiny PHP forum - vulns</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded" xml:lang="en">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22257" xml:lang="en">22257</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015436" xml:lang="en">1015436</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/320" xml:lang="en">320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18293" xml:lang="en">18293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/14/summary.html" xml:lang="en">http://evuln.com/vulns/14/summary.html</vuln:reference>
    </vuln:references>
    <vuln:summary>TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0104">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.46"/>
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.47"/>
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.48"/>
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.49"/>
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.499"/>
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ralph_capper:tinyphpforum:3.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.6</vuln:product>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.499</vuln:product>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.46</vuln:product>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.49</vuln:product>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.48</vuln:product>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.5</vuln:product>
      <vuln:product>cpe:/a:ralph_capper:tinyphpforum:3.47</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0104</vuln:cve-id>
    <vuln:published-datetime>2006-01-06T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:20.377-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-06T08:49:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0054" xml:lang="en">ADV-2006-0054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded" xml:lang="en">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18293" xml:lang="en">18293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/14/summary.html" xml:lang="en">http://evuln.com/vulns/14/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/14/exploit.html" xml:lang="en">http://evuln.com/vulns/14/exploit.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16163" xml:lang="en">16163</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22258" xml:lang="en">22258</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015436" xml:lang="en">1015436</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/320" xml:lang="en">320</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in TinyPHPForum 3.6 and earlier allows remote attackers to create a new user account, create a new topic, or view the profile of a user account, as demonstrated via a .. (dot dot) in the uname parameter to profile.php.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0105">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:postgresql:postgresql:8.1.0</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.0.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.1.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.0</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.0.5</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.0.4</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.0.3</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0105</vuln:cve-id>
    <vuln:published-datetime>2006-01-10T15:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:20.470-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T08:49:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://archives.postgresql.org/pgsql-announce/2006-01/msg00001.php" xml:lang="en">[pgsql-announce] 20060109 CRITICAL RELEASE: Minor Releases to Fix DoS Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0114" xml:lang="en">ADV-2006-0114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24049" xml:lang="en">postgresql-connection-request-dos(24049)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16201" xml:lang="en">16201</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421592/100/0/threaded" xml:lang="en">20060111 PostgreSQL security releases 8.0.6 and 8.1.2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.postgresql.org/about/news.456" xml:lang="en">http://www.postgresql.org/about/news.456</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015482" xml:lang="en">1015482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/327" xml:lang="en">327</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18419" xml:lang="en">18419</vuln:reference>
    </vuln:references>
    <vuln:summary>PostgreSQL 8.0.x before 8.0.6 and 8.1.x before 8.1.2, when running on Windows, allows remote attackers to cause a denial of service (postmaster exit and no new connections) via a large number of simultaneous connection requests.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0106">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wine:wine:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wine:wine:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:wine:wine:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:wine:wine:2005-09-30"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wine:wine:0.9.2</vuln:product>
      <vuln:product>cpe:/a:wine:wine:0.9.5</vuln:product>
      <vuln:product>cpe:/a:wine:wine:0.9.4</vuln:product>
      <vuln:product>cpe:/a:wine:wine:2005-09-30</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0106</vuln:cve-id>
    <vuln:published-datetime>2006-01-06T13:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:20.547-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:45:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18323" xml:lang="en">18323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=346197" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=346197</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0098" xml:lang="en">ADV-2006-0098</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.immunitysec.com/pipermail/dailydave/2006-January/002806.html" xml:lang="en">[Dailydave] 20060105 WMF goes away :&lt;</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/23846" xml:lang="en">win-wmf-execute-code(23846)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/422128/100/0/threaded" xml:lang="en">20060117 ERRATA: [ GLSA 200601-09 ] Wine: Windows Metafile SETABORTPROC vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2006_02_sr.html" xml:lang="en">SUSE-SR:2006:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:014" xml:lang="en">MDKSA-2006:014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200601-09.xml" xml:lang="en">GLSA-200601-09</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-954" xml:lang="en">DSA-954</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18578" xml:lang="en">18578</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18549" xml:lang="en">18549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18451" xml:lang="en">18451</vuln:reference>
    </vuln:references>
    <vuln:summary>gdi/driver.c and gdi/printdrv.c in Wine 20050930, and other versions, implement the SETABORTPROC GDI Escape function call for Windows Metafile (WMF) files, which allows attackers to execute arbitrary code, the same vulnerability as CVE-2005-4560 but in a different codebase.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0107">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:idea_development_id_oy:timecan_cms"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:idea_development_id_oy:timecan_cms</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0107</vuln:cve-id>
    <vuln:published-datetime>2006-01-06T19:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:22.717-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:36:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16159" xml:lang="en">16159</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22252" xml:lang="en">22252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18324" xml:lang="en">18324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24014" xml:lang="en">timecancms-sql-injection(24014)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the viewID parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Due to the unavailability of the original source, it cannot be determined if this is the same issue as identified by CVE-2006-0108.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0108">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:idea_development_id_oy:timecan_cms"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:idea_development_id_oy:timecan_cms</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0108</vuln:cve-id>
    <vuln:published-datetime>2006-01-06T19:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:20.720-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:37:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0078" xml:lang="en">ADV-2006-0078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22253" xml:lang="en">22253</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22252" xml:lang="en">22252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24014" xml:lang="en">timecancms-sql-injection(24014)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in mcl_login.asp in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the email parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Due to the unavailability of the original source, it cannot be determined if this is the same issue as identified by CVE-2006-0107.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0109">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:modular_merchant:shopping_cart"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:modular_merchant:shopping_cart</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0109</vuln:cve-id>
    <vuln:discovered-datetime>2006-01-06T00:00:00.000-05:00</vuln:discovered-datetime>
    <vuln:published-datetime>2006-01-06T19:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:21.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:40:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18320" xml:lang="en">18320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0076" xml:lang="en">ADV-2006-0076</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16160" xml:lang="en">16160</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22243" xml:lang="en">22243</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.modularmerchant.com/forums/viewtopic.php?t=46" xml:lang="en">http://www.modularmerchant.com/forums/viewtopic.php?t=46</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://osvdb.org/ref/22/22243-modular.txt" xml:lang="en">http://osvdb.org/ref/22/22243-modular.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2006-February/000548.html" xml:lang="en">20060214 vendor ack/fix 22243: Modular Merchant Marketplace Shopping Cart category.php cat Variable XSS (fwd)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting vulnerability in category.php in Modular Merchant Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0110">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:javier_suarez_sanz:foro_domus:2.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:javier_suarez_sanz:foro_domus:2.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0110</vuln:cve-id>
    <vuln:discovered-datetime>2006-01-06T00:00:00.000-05:00</vuln:discovered-datetime>
    <vuln:published-datetime>2006-01-06T19:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:21.080-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-05-11T10:55:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0073" xml:lang="en">ADV-2006-0073</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16154" xml:lang="en">16154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421056/100/0/threaded" xml:lang="en">20060106 [eVuln] Proyecto Domus 'email' XSS Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22263" xml:lang="en">22263</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18327" xml:lang="en">18327</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/16/summary.html" xml:lang="en">http://evuln.com/vulns/16/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24020" xml:lang="en">domus-escribir-xss(24020)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to inject arbitrary web script via the email parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0111">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:boxcar_media:shopping_cart"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:boxcar_media:shopping_cart</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0111</vuln:cve-id>
    <vuln:discovered-datetime>2006-01-06T00:00:00.000-05:00</vuln:discovered-datetime>
    <vuln:published-datetime>2006-01-06T19:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:21.173-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:41:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24019" xml:lang="en">boxcar-index-xss(24019)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0080" xml:lang="en">ADV-2006-0080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22360" xml:lang="en">22360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://osvdb.org/ref/22/22360-boxcar.txt" xml:lang="en">http://osvdb.org/ref/22/22360-boxcar.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting vulnerability in index.php in Boxcar Media Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) parent or (2) pg parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0112">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:enhanced_simple_php_gallery:enhanced_simple_php_gallery:1.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:enhanced_simple_php_gallery:enhanced_simple_php_gallery:1.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0112</vuln:cve-id>
    <vuln:published-datetime>2006-01-06T20:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:21.237-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:33:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0036" xml:lang="en">ADV-2006-0036</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22201" xml:lang="en">22201</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18310" xml:lang="en">18310</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://osvdb.org/ref/22/22201-espg.txt" xml:lang="en">http://osvdb.org/ref/22/22201-espg.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in Enhanced Simple PHP Gallery 1.7 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0113">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:enhanced_simple_php_gallery:enhanced_simple_php_gallery:1.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:enhanced_simple_php_gallery:enhanced_simple_php_gallery:1.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0113</vuln:cve-id>
    <vuln:published-datetime>2006-01-06T20:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:23.733-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:34:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18310" xml:lang="en">18310</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://osvdb.org/ref/22/22201-espg.txt" xml:lang="en">http://osvdb.org/ref/22/22201-espg.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22417" xml:lang="en">22417</vuln:reference>
    </vuln:references>
    <vuln:summary>Enhanced Simple PHP Gallery 1.7 allows remote attackers to obtain the full path of the application via a direct request to sp_helper_functions.php, which leaks the pathname in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0114">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:joomla:joomla:1.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0114</vuln:cve-id>
    <vuln:discovered-datetime>2006-01-09T00:00:00.000-05:00</vuln:discovered-datetime>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-06-06T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-09T08:26:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24042" xml:lang="en">joomla-vcard-information-disclosure(24042)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0097" xml:lang="en">ADV-2006-0097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16185" xml:lang="en">16185</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18361" xml:lang="en">18361</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://forum.joomla.org/index.php/topic,29031.0.html" xml:lang="en">http://forum.joomla.org/index.php/topic,29031.0.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://forge.joomla.org/sf/go/artf2950" xml:lang="en">http://forge.joomla.org/sf/go/artf2950</vuln:reference>
    </vuln:references>
    <vuln:summary>The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to obtain valid e-mail addresses to conduct spam attacks by modifying the contact_id parameter to index2.php.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0115">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oneplug_solutions:oneplug_cms"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oneplug_solutions:oneplug_cms</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0115</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-08T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-09T08:28:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0079" xml:lang="en">ADV-2006-0079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16155" xml:lang="en">16155</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22250" xml:lang="en">22250</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22249" xml:lang="en">22249</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22248" xml:lang="en">22248</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18325" xml:lang="en">18325</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://osvdb.org/ref/22/22248-oneplug.txt" xml:lang="en">http://osvdb.org/ref/22/22248-oneplug.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL commands via the (1) Press_Release_ID parameter in press/details.asp, (2) Service_ID parameter in services/details.asp, and (3) Product_ID parameter in products/details.asp.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0116">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:inetstore:inetstore_online"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:inetstore:inetstore_online</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0116</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:21.563-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-09T08:29:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0075" xml:lang="en">ADV-2006-0075</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16156" xml:lang="en">16156</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/423137/100/0/threaded" xml:lang="en">20060126 Re: [OSVDB Mods] iNETstore E Commerce Solution - Cross Site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22251" xml:lang="en">22251</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2006-January/000515.html" xml:lang="en">20060127 vendor confirms versions: iNETstore E Commerce Solution - Cross Site Scripting (fwd)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18322" xml:lang="en">18322</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://osvdb.org/ref/22/22251-inetstore.txt" xml:lang="en">http://osvdb.org/ref/22/22251-inetstore.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting vulnerability search.inetstore in iNETstore Ebusiness Software 2.0 allows remote attackers to inject arbitrary web script or HTML via the searchterm parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0117">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4::fp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4::fp2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_enterprise_server:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_enterprise_server:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_enterprise_server:6.5.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4::fp1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_enterprise_server:6.5.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4::fp2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0117</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:21.673-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-09T10:06:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16158" xml:lang="en">16158</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18328" xml:lang="en">18328</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0081" xml:lang="en">ADV-2006-0081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument" xml:lang="en">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument" xml:lang="en">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg27007054" xml:lang="en">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24205" xml:lang="en">lotus-cdtomime-dos(24205)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in IBM Lotus Notes and Domino Server before 6.5.5 allows attackers to cause a denial of service (router crash or hang) via unspecified vectors involving "CD to MIME Conversion".</vuln:summary>
  </entry>
  <entry id="CVE-2006-0118">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4::fp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4::fp2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_enterprise_server:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_enterprise_server:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_enterprise_server:6.5.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4::fp1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_enterprise_server:6.5.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4::fp2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0118</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:21.767-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-09T10:08:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16158" xml:lang="en">16158</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18328" xml:lang="en">18328</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0081" xml:lang="en">ADV-2006-0081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument" xml:lang="en">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument" xml:lang="en">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg27007054" xml:lang="en">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24206" xml:lang="en">lotus-long-formula-bo(24206)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, allows attackers to cause a denial of service (deep recursion leading to stack overflow and crash) via long formulas.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0119">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4::fp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4::fp2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_enterprise_server:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_enterprise_server:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_enterprise_server:6.5.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4::fp1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_enterprise_server:6.5.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4::fp2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0119</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-06T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-09T13:06:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16158" xml:lang="en">16158</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18328" xml:lang="en">18328</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/27413" xml:lang="en">domino-smtp-nrouter-dos(27413)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24211" xml:lang="en">lotus-web-unspecified-xss(24211)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24207" xml:lang="en">lotus-multiple-unspecified(24207)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/2564" xml:lang="en">ADV-2006-2564</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0081" xml:lang="en">ADV-2006-0081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/18020" xml:lang="en">18020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/438461/100/0/threaded" xml:lang="en">20060626 SYMSA-2006-006: Lotus Domino SMTP Based Denial of Service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/f97fe7cfd9a8113b8525709200001db4?OpenDocument&amp;Highlight=0,GPKS6C9J67" xml:lang="en">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/f97fe7cfd9a8113b8525709200001db4?OpenDocument&amp;Highlight=0,GPKS6C9J67</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/e4deb1cbb011c747852570e4001ba9bb?OpenDocument&amp;Highlight=0,GPKS5YQGPT" xml:lang="en">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/e4deb1cbb011c747852570e4001ba9bb?OpenDocument&amp;Highlight=0,GPKS5YQGPT</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/de2ab57a5b9547848525701b00420c2c?OpenDocument&amp;Highlight=0,KSPR699NBP" xml:lang="en">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/de2ab57a5b9547848525701b00420c2c?OpenDocument&amp;Highlight=0,KSPR699NBP</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/d1150fc9c5dec8b18525709200001da6?OpenDocument&amp;Highlight=0,GPKS6C9J67" xml:lang="en">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/d1150fc9c5dec8b18525709200001da6?OpenDocument&amp;Highlight=0,GPKS6C9J67</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/9a1650d1a771f3078525702a00420def?OpenDocument&amp;Highlight=0,HSAO6BNL6Y" xml:lang="en">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/9a1650d1a771f3078525702a00420def?OpenDocument&amp;Highlight=0,HSAO6BNL6Y</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/94a77eb898843aca8525709200001de1?OpenDocument&amp;Highlight=0,JGAN6B6TZ3" xml:lang="en">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/94a77eb898843aca8525709200001de1?OpenDocument&amp;Highlight=0,JGAN6B6TZ3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg27007054" xml:lang="en">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1016390" xml:lang="en">1016390</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20855" xml:lang="en">20855</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to "potential security issues" as identified by SPR numbers (1) GPKS6C9J67 in Agents, (2) JGAN6B6TZ3 and (3) KSPR699NBP in the Router, (4) GPKS5YQGPT in Security, or (5) HSAO6BNL6Y in the Web Server. NOTE: vector 3 is related to an issue in NROUTER in IBM Lotus Notes and Domino Server before 6.5.4 FP1, 6.5.5, and 7.0, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted vCal meeting request sent via SMTP (aka SPR# KSPR699NBP).</vuln:summary>
  </entry>
  <entry id="CVE-2006-0120">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4::fp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4::fp2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_enterprise_server:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_enterprise_server:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_enterprise_server:6.5.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4::fp1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_enterprise_server:6.5.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4::fp2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0120</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:21.937-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-09T13:15:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16158" xml:lang="en">16158</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18328" xml:lang="en">18328</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0081" xml:lang="en">ADV-2006-0081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ced5f873baea4e8b852570e4001baa6d?OpenDocument" xml:lang="en">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ced5f873baea4e8b852570e4001baa6d?OpenDocument</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ad0dd14aa109f96b852570e4001bb08c?OpenDocument" xml:lang="en">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ad0dd14aa109f96b852570e4001bb08c?OpenDocument</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/5f166a44ee743b2c852570e4001baf31?OpenDocument" xml:lang="en">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/5f166a44ee743b2c852570e4001baf31?OpenDocument</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/4118a1f266afb26c852570e4001baf5e?OpenDocument" xml:lang="en">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/4118a1f266afb26c852570e4001baf5e?OpenDocument</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/2bb4f466a9e986ae852570e4001babbb?OpenDocument" xml:lang="en">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/2bb4f466a9e986ae852570e4001babbb?OpenDocument</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/040482aeb1416bb7852570e4001badd6?OpenDocument" xml:lang="en">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/040482aeb1416bb7852570e4001badd6?OpenDocument</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/258394eaa824f2c08525708a004209d3?OpenDocument" xml:lang="en">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/258394eaa824f2c08525708a004209d3?OpenDocument</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg27007054" xml:lang="en">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24217" xml:lang="en">lotus-ssl-keyring-dos(24217)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24216" xml:lang="en">lotus-certificate-parsing-dos(24216)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24215" xml:lang="en">lotus-delete-attachment-dos(24215)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24214" xml:lang="en">lotus-bmp-dos(24214)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24213" xml:lang="en">lotus-compact-dos(24213)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24212" xml:lang="en">lotus-outofoffice-dos(24212)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an "Out Of Office" agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap images (MYAA6FH5HW), (4) the "Delete Attachment" action (YPHG6844LD), (5) parsing certificates from a remote Certificate Table (AELE6DZFJW), and (6) creating a SSL key ring with the Domino Administration client (NSUA4FQPTN).</vuln:summary>
  </entry>
  <entry id="CVE-2006-0121">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4::fp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.5.4::fp2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_enterprise_server:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_enterprise_server:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:6.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_enterprise_server:6.5.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4::fp1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_enterprise_server:6.5.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.4::fp2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:6.5.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0121</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:22.033-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-09T13:17:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16158" xml:lang="en">16158</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18328" xml:lang="en">18328</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0081" xml:lang="en">ADV-2006-0081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/2221243535d88a2b8525701b00420cd6?OpenDocument&amp;Highlight=0,MKIN693QUT" xml:lang="en">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/2221243535d88a2b8525701b00420cd6?OpenDocument&amp;Highlight=0,MKIN693QUT</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/20f66e356a76c90f8525702a00420e08?OpenDocument&amp;Highlight=0,MKIN67MQVW" xml:lang="en">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/20f66e356a76c90f8525702a00420e08?OpenDocument&amp;Highlight=0,MKIN67MQVW</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg27007054" xml:lang="en">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24223" xml:lang="en">lotus-ssl-handshake-dos(24223)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (memory consumption and crash) via unknown vectors related to (1) unspecified vectors during the SSL handshake (SPR# MKIN67MQVW), (2) the stash file during the SSL handshake (SPR# MKIN693QUT), and possibly other vectors. NOTE: due to insufficient information in the original vendor advisory, it is not clear whether there is an attacker role in other memory leaks that are specified in the advisory.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0122">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:aquifer_cms:aquifer_cms"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aquifer_cms:aquifer_cms</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0122</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:22.097-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-09T13:18:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22247" xml:lang="en">22247</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0074" xml:lang="en">ADV-2006-0074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16162" xml:lang="en">16162</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18326" xml:lang="en">18326</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://osvdb.org/ref/22/22247-aquifer.txt" xml:lang="en">http://osvdb.org/ref/22/22247-aquifer.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2006-January/000509.html" xml:lang="en">20060124 vendor ack/fix: Aquifer CMS Index.asp Keyword Variable XSS (fwd)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Public/Index.asp in Aquifer CMS allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0123">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adn_forum:adn_forum:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adn_forum:adn_forum:1.0b"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adn_forum:adn_forum:1.0b</vuln:product>
      <vuln:product>cpe:/a:adn_forum:adn_forum:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0123</vuln:cve-id>
    <vuln:discovered-datetime>2006-01-05T00:00:00.000-05:00</vuln:discovered-datetime>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-08T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-09T13:23:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0077" xml:lang="en">ADV-2006-0077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16157" xml:lang="en">16157</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420990/100/0/threaded" xml:lang="en">20060105 [eVuln] ADNForum Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22241" xml:lang="en">22241</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22240" xml:lang="en">22240</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015445" xml:lang="en">1015445</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18300" xml:lang="en">18300</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/15/summary.html" xml:lang="en">http://evuln.com/vulns/15/summary.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in ADN Forum 1.0b allow remote attackers to execute arbitrary SQL commands via the (1) fid parameter in index.php and (2) pagid parameter in verpag.php, and possibly other vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0124">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adn_forum:adn_forum:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adn_forum:adn_forum:1.0b"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adn_forum:adn_forum:1.0b</vuln:product>
      <vuln:product>cpe:/a:adn_forum:adn_forum:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0124</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:22.250-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-09T13:24:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0077" xml:lang="en">ADV-2006-0077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16157" xml:lang="en">16157</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420990/100/0/threaded" xml:lang="en">20060105 [eVuln] ADNForum Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18300" xml:lang="en">18300</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/15/summary.html" xml:lang="en">http://evuln.com/vulns/15/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22242" xml:lang="en">22242</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015445" xml:lang="en">1015445</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in crear.php in ADN Forum 1.0b allows remote attackers to inject arbitrary web script or HTML via the titulo parameter, which is used by the "Topic name" field.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0125">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:appserv_open_project:appserv:2.4.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:appserv_open_project:appserv:2.4.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0125</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:22.330-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-09T13:27:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0053" xml:lang="en">ADV-2006-0053</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22228" xml:lang="en">22228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18163" xml:lang="en">18163</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16166" xml:lang="en">16166</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in appserv/main.php in AppServ 2.4.5 allows remote attackers to include arbitrary files via the appserv_root parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  There is not enough detail from these third party sources to know whether this is directory traversal, remote file include, or another issue.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0126">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rxvt-unicode:rxvt-unicode:6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rxvt-unicode:rxvt-unicode:6.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0126</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:22.437-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-09T13:30:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22223" xml:lang="en">22223</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18301" xml:lang="en">18301</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0052" xml:lang="en">ADV-2006-0052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://dist.schmorp.de/rxvt-unicode/Changes" xml:lang="en">http://dist.schmorp.de/rxvt-unicode/Changes</vuln:reference>
    </vuln:references>
    <vuln:summary>rxvt-unicode before 6.3, on certain platforms that use openpty and non-Unix pty devices such as Linux and most BSD platforms, does not maintain the intended permissions of tty devices, which allows local users to gain read and write access to the devices.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0127">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rockliffe:mailsite:6.1.22.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rockliffe:mailsite:6.1.22.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0127</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:22.547-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication approximated="true">SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:05:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt" xml:lang="en">http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22229" xml:lang="en">22229</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18318" xml:lang="en">18318</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040969.html" xml:lang="en">20060104 Rockliffe Directory Transversal Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0055" xml:lang="en">ADV-2006-0055</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041039.html" xml:lang="en">20060105 Re: Rockliffe Directory Transversal Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote authenticated users to rename the folders of other users via a .. (dot dot) in the RENAME command.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0128">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rockliffe:mailsite:6.1.22.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rockliffe:mailsite:6.1.22.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0128</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:26.123-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:06:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt" xml:lang="en">http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040969.html" xml:lang="en">20060104 Rockliffe Directory Transversal Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39991" xml:lang="en">rockliffe-imap-unspecified-bo(39991)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote attackers to have an unknown impact via unknown attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0129">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rockliffe:mailsite:7.0.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rockliffe:mailsite:7.0.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0129</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:22.720-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:08:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18318" xml:lang="en">18318</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt" xml:lang="en">http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0055" xml:lang="en">ADV-2006-0055</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22230" xml:lang="en">22230</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040970.html" xml:lang="en">20060104 Rockliffe Mailsite User Enumeration Flaw</vuln:reference>
    </vuln:references>
    <vuln:summary>Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier generates different responses depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames via user requests to TCP port 106.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0130">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rockliffe:mailsite:7.0.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rockliffe:mailsite:7.0.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0130</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:26.420-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:10:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt" xml:lang="en">http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040970.html" xml:lang="en">20060104 Rockliffe Mailsite User Enumeration Flaw</vuln:reference>
    </vuln:references>
    <vuln:summary>Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier allows remote attackers to attempt authentication with an unlimited number of user account names and passwords without denying connections, limiting the rate of connections, or locking out an account.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0131">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:boastmachine:boastmachine:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:boastmachine:boastmachine:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0131</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:26.577-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420969/100/0/threaded" xml:lang="en">20060105 [ECHO_ADV_25$2006] Full path disclosure on boastMachine v3.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://echo.or.id/adv/adv26-K-159-2006.txt" xml:lang="en">http://echo.or.id/adv/adv26-K-159-2006.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>boastMachine 3.1 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php and (2) side_menu.php, which reveals the path in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0132">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:webftp:webftp:1.2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webftp:webftp:1.2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0132</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:22.923-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18355" xml:lang="en">18355</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0090" xml:lang="en">ADV-2006-0090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16175" xml:lang="en">16175</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420973/100/0/threaded" xml:lang="en">20060104 SysCP WebFTP local file inclusion vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24018" xml:lang="en">webftp-language-file-include(24018)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in webftp.php in SysCP WebFTP 1.2.6 and possibly earlier allows remote attackers to include and execute arbitrary local PHP scripts, and possibly read other types of files, via a .. (dot dot) and a trailing null in the webftp_language parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0133">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.3_ml03"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:5.3_ml03</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0133</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:26.873-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>3.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:16:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16103" xml:lang="en">16103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16102" xml:lang="en">16102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420589/100/0/threaded" xml:lang="en">20060101 [xfocus-SD-060101]AIX getCommand&amp;getShell two vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015429" xml:lang="en">1015429</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and read partial contents of certain files via a .. (dot dot) in the argument to (1) getCommand.new (aka getCommand) and (2) getShell, a different vulnerability than CVE-2005-4273.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0134">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:thewebforum:thewebforum:1.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:thewebforum:thewebforum:1.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0134</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:23.080-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:18:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0093" xml:lang="en">ADV-2006-0093</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16161" xml:lang="en">16161</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421039/100/0/threaded" xml:lang="en">20060106 [eVuln] TheWebForum Script Insertion and Authentication Bypass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015450" xml:lang="en">1015450</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18392" xml:lang="en">18392</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/17/summary.html" xml:lang="en">http://evuln.com/vulns/17/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/17/exploit.html" xml:lang="en">http://evuln.com/vulns/17/exploit.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24007" xml:lang="en">thewebforum-register-xss(24007)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22295" xml:lang="en">22295</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in register.php in TheWebForum (twf) 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the www parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0135">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:thewebforum:thewebforum:1.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:thewebforum:thewebforum:1.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0135</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:23.157-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:20:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0093" xml:lang="en">ADV-2006-0093</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16161" xml:lang="en">16161</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421039/100/0/threaded" xml:lang="en">20060106 [eVuln] TheWebForum Script Insertion and Authentication Bypass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015450" xml:lang="en">1015450</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18392" xml:lang="en">18392</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/17/summary.html" xml:lang="en">http://evuln.com/vulns/17/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/17/exploit.html" xml:lang="en">http://evuln.com/vulns/17/exploit.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24027" xml:lang="en">thewebforum-login-sql-injection(24027)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22294" xml:lang="en">22294</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/321" xml:lang="en">321</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the username parameter (aka the u variable).</vuln:summary>
  </entry>
  <entry id="CVE-2006-0136">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phanatic_softwares:chimera_web_portal:0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phanatic_softwares:chimera_web_portal:0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0136</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:23.250-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:24:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0025" xml:lang="en">ADV-2006-0025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16113" xml:lang="en">16113</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420669/100/0/threaded" xml:lang="en">20060101 [eVuln] Chimera Web Portal System Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/7/summary.html" xml:lang="en">http://evuln.com/vulns/7/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/7/exploit.html" xml:lang="en">http://evuln.com/vulns/7/exploit.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in the guestbook module in modules.php in Phanatic Softwares Chimera Web Portal System 0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) comment_poster, (2) comment_poster_email, (3) comment_poster_homepage, and (4) comment_text parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0137">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phanatic_softwares:chimera_web_portal:0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phanatic_softwares:chimera_web_portal:0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0137</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:23.347-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:24:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0025" xml:lang="en">ADV-2006-0025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16113" xml:lang="en">16113</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/420669/100/0/threaded" xml:lang="en">20060101 [eVuln] Chimera Web Portal System Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/7/summary.html" xml:lang="en">http://evuln.com/vulns/7/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/7/exploit.html" xml:lang="en">http://evuln.com/vulns/7/exploit.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/23963" xml:lang="en">chimera-linkcategory-sql-injection(23963)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22420" xml:lang="en">22420</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in linkcategory.php in Phanatic Softwares Chimera Web Portal System 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0138">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:amsn:amsn"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:amsn:amsn</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0138</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:27.607-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:26:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securiteam.com/exploits/5JP090KHFQ.html" xml:lang="en">http://www.securiteam.com/exploits/5JP090KHFQ.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22186" xml:lang="en">22186</vuln:reference>
    </vuln:references>
    <vuln:summary>aMSN (aka Alvaro's Messenger) allows remote attackers to cause a denial of service (client hang and termination of client's instant-messaging session) by repeatedly sending crafted data to the default file-transfer port (TCP 6891).</vuln:summary>
  </entry>
  <entry id="CVE-2006-0139">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pd9_software:megabbs:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pd9_software:megabbs:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pd9_software:megabbs:2.1</vuln:product>
      <vuln:product>cpe:/a:pd9_software:megabbs:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0139</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T13:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:25.750-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-09T13:13:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16168" xml:lang="en">16168</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.pd9soft.com/megabbs/forums/thread-view.asp?tid=4924" xml:lang="en">http://www.pd9soft.com/megabbs/forums/thread-view.asp?tid=4924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hamid.ir/security/megabbs.txt" xml:lang="en">http://www.hamid.ir/security/megabbs.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18342" xml:lang="en">18342</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0095" xml:lang="en">ADV-2006-0095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24050" xml:lang="en">megabbs-sendprivatemessage-disclosure(24050)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015452" xml:lang="en">1015452</vuln:reference>
    </vuln:references>
    <vuln:summary>The send-private-message functionality (send-private-message.asp) in PD9 Software MegaBBS 2.1 allows remote attackers to read private messages of other users via a modified replyid parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0140">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:navboard:navboard:16"/>
        <cpe-lang:fact-ref name="cpe:/a:navboard:navboard:17:beta2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:navboard:navboard:17:beta2</vuln:product>
      <vuln:product>cpe:/a:navboard:navboard:16</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0140</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T14:07:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:25.830-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24021" xml:lang="en">navboard-post-xss(24021)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0092" xml:lang="en">ADV-2006-0092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16165" xml:lang="en">16165</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421149/100/0/threaded" xml:lang="en">20060107 [eVuln] NavBoard BBcode XSS Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22277" xml:lang="en">22277</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18345" xml:lang="en">18345</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/19/summary.html" xml:lang="en">http://evuln.com/vulns/19/summary.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in post.php in NavBoard V16 Stable(2.6.0) and V17beta2 allows remote attackers to inject arbitrary web script or HTML via the (1) b, (2) textlarge, and (3) url bbcode tags.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0141">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:eudora:internet_mail_server:3.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:eudora:internet_mail_server:3.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:eudora:internet_mail_server:3.2.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eudora:internet_mail_server:3.2.8</vuln:product>
      <vuln:product>cpe:/a:eudora:internet_mail_server:3.2.7</vuln:product>
      <vuln:product>cpe:/a:eudora:internet_mail_server:3.2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0141</vuln:cve-id>
    <vuln:discovered-datetime>2006-01-09T00:00:00.000-05:00</vuln:discovered-datetime>
    <vuln:published-datetime>2006-01-09T14:07:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:25.923-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-05-10T15:59:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.eudora.co.nz/updates.html" xml:lang="en">http://www.eudora.co.nz/updates.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18356" xml:lang="en">18356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0099" xml:lang="en">ADV-2006-0099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16179" xml:lang="en">16179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24033" xml:lang="en">eims-corrupted-mail-dos(24033)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24032" xml:lang="en">eims-ntlm-auth-dos(24032)</vuln:reference>
    </vuln:references>
    <vuln:summary>Qualcomm Eudora Internet Mail Server (EIMS) before 3.2.8 allows remote attackers to cause a denial of service (crash) via (1) malformed NTLM authentication requests, or a malformed (2) Incoming Mail X or (3) Temporary Mail file.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0142">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:andromeda_software:andromeda:1.9.3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:andromeda_software:andromeda:1.9.3.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0142</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T14:07:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:26.017-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T09:01:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0096" xml:lang="en">ADV-2006-0096</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16183" xml:lang="en">16183</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18359" xml:lang="en">18359</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24031" xml:lang="en">andromeda-script-xss(24031)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in andromeda.php in Andromeda 1.9.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the s parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0143">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:::server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp1:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp2:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp3:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:datacenter_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:datacenter_64-bit:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:enterprise_64-bit:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:standard_64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:web:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_me</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:standard::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:r2:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise_64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98se</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp3:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:::server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:datacenter_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp1:advanced_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp2:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:web:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:datacenter_64-bit:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:enterprise:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:advanced_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0143</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T15:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-22T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T08:58:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015453" xml:lang="en">1015453</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24044" xml:lang="en">win-gre-wmf-dos(24044)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0115" xml:lang="en">ADV-2006-0115</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16167" xml:lang="en">16167</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421258/100/0/threaded" xml:lang="en">20060109 [UPDATE]Microsoft Windows GRE WMF Format Multiple Unauthorized Memory Access Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421257/100/0/threaded" xml:lang="en">20060107 Microsoft Windows GRE WMF Format Multiple Memory Overrun Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html" xml:lang="en">http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://blogs.technet.com/msrc/archive/2006/01/09/417198.aspx" xml:lang="en">http://blogs.technet.com/msrc/archive/2006/01/09/417198.aspx</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file containing (1) ExtCreateRegion or (2) ExtEscape function calls with arguments with inconsistent lengths.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0144">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache2triad:apache2triad"/>
        <cpe-lang:fact-ref name="cpe:/a:php:pear:0.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:pear:0.2.2</vuln:product>
      <vuln:product>cpe:/a:apache2triad:apache2triad</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0144</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-06-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-10T08:28:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18390" xml:lang="en">18390</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24076" xml:lang="en">gopear-proxy-redirection(24076)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0148" xml:lang="en">ADV-2006-0148</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16174" xml:lang="en">16174</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421469/100/0/threaded" xml:lang="en">20060109 New PEAR / Apache2Triad Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://apache2triad.net/forums/viewtopic.php?p=14670" xml:lang="en">http://apache2triad.net/forums/viewtopic.php?p=14670</vuln:reference>
    </vuln:references>
    <vuln:summary>The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0145">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.6:beta"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:netbsd:netbsd:2.0.3</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:2.0</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:2.1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6:beta</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6.1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:2.0.2</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:2.0.1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.6.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0145</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:28.777-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-10T08:31:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16173" xml:lang="en">16173</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securitylab.net/research/2006/02/advisory_netbsd_openbsd_kernfs.html" xml:lang="en">http://www.securitylab.net/research/2006/02/advisory_netbsd_openbsd_kernfs.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/423827/100/0/threaded" xml:lang="en">20060202 [SLAB] NetBSD / OpenBSD kernfs_xread patch evasion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22293" xml:lang="en">22293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18712" xml:lang="en">18712</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18388" xml:lang="en">18388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-001.txt.asc" xml:lang="en">NetBSD-SA2006-001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24035" xml:lang="en">netbsd-kernfs-memory-disclosure(24035)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/405" xml:lang="en">405</vuln:reference>
    </vuln:references>
    <vuln:summary>The kernfs_xread function in kernfs in NetBSD 1.6 through 2.1, and OpenBSD 3.8, does not properly validate file offsets against negative 32-bit values that occur as a result of truncation, which allows local users to read arbitrary kernel memory and gain privileges via the lseek system call.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0146">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:john_lim:adodb:4.66"/>
        <cpe-lang:fact-ref name="cpe:/a:john_lim:adodb:4.68"/>
        <cpe-lang:fact-ref name="cpe:/a:mantis:mantis:0.19.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mantis:mantis:1.0.0_rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediabeez:mediabeez"/>
        <cpe-lang:fact-ref name="cpe:/a:moodle:moodle:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postnuke_software_foundation:postnuke:0.761"/>
        <cpe-lang:fact-ref name="cpe:/a:the_cacti_group:cacti:0.8.6g"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mediabeez:mediabeez</vuln:product>
      <vuln:product>cpe:/a:mantis:mantis:0.19.4</vuln:product>
      <vuln:product>cpe:/a:moodle:moodle:1.5.3</vuln:product>
      <vuln:product>cpe:/a:john_lim:adodb:4.66</vuln:product>
      <vuln:product>cpe:/a:mantis:mantis:1.0.0_rc4</vuln:product>
      <vuln:product>cpe:/a:postnuke_software_foundation:postnuke:0.761</vuln:product>
      <vuln:product>cpe:/a:john_lim:adodb:4.68</vuln:product>
      <vuln:product>cpe:/a:the_cacti_group:cacti:0.8.6g</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0146</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-06-14T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-10T08:39:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.xaraya.com/index.php/news/569" xml:lang="en">http://www.xaraya.com/index.php/news/569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16187" xml:lang="en">16187</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/423784/100/0/threaded" xml:lang="en">20060202 Bug for libs in php link directory 2.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22290" xml:lang="en">22290</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml" xml:lang="en">GLSA-200604-07</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1031" xml:lang="en">DSA-1031</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1030" xml:lang="en">DSA-1030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1029" xml:lang="en">DSA-1029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2005-64/advisory/" xml:lang="en">http://secunia.com/secunia_research/2005-64/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19699" xml:lang="en">19699</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19591" xml:lang="en">19591</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19590" xml:lang="en">19590</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19563" xml:lang="en">19563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19555" xml:lang="en">19555</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18720" xml:lang="en">18720</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18276" xml:lang="en">18276</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18260" xml:lang="en">18260</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18233" xml:lang="en">18233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/17418" xml:lang="en">17418</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24051" xml:lang="en">adodb-server-command-execution(24051)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1419" xml:lang="en">ADV-2006-1419</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1305" xml:lang="en">ADV-2006-1305</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1304" xml:lang="en">ADV-2006-1304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0447" xml:lang="en">ADV-2006-0447</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0370" xml:lang="en">ADV-2006-0370</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0105" xml:lang="en">ADV-2006-0105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0104" xml:lang="en">ADV-2006-0104</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0103" xml:lang="en">ADV-2006-0103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0102" xml:lang="en">ADV-2006-0102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0101" xml:lang="en">ADV-2006-0101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/466171/100/0/threaded" xml:lang="en">20070418 MediaBeez Sql query Execution .. Wear isn't ?? :)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/430448/100/0/threaded" xml:lang="en">20060409 PhpOpenChat 3.0.x ADODB Server.php </vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.maxdev.com/Article550.phtml" xml:lang="en">http://www.maxdev.com/Article550.phtml</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/713" xml:lang="en">713</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24954" xml:lang="en">24954</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19691" xml:lang="en">19691</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19600" xml:lang="en">19600</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18267" xml:lang="en">18267</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18254" xml:lang="en">18254</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html" xml:lang="en">http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html</vuln:reference>
    </vuln:references>
    <vuln:summary>The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0147">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:john_lim:adodb:4.66"/>
        <cpe-lang:fact-ref name="cpe:/a:john_lim:adodb:4.68"/>
        <cpe-lang:fact-ref name="cpe:/a:mantis:mantis:0.19.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mantis:mantis:1.0.0_rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:moodle:moodle:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postnuke_software_foundation:postnuke:0.761"/>
        <cpe-lang:fact-ref name="cpe:/a:the_cacti_group:cacti:0.8.6g"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mantis:mantis:0.19.4</vuln:product>
      <vuln:product>cpe:/a:moodle:moodle:1.5.3</vuln:product>
      <vuln:product>cpe:/a:john_lim:adodb:4.66</vuln:product>
      <vuln:product>cpe:/a:mantis:mantis:1.0.0_rc4</vuln:product>
      <vuln:product>cpe:/a:postnuke_software_foundation:postnuke:0.761</vuln:product>
      <vuln:product>cpe:/a:john_lim:adodb:4.68</vuln:product>
      <vuln:product>cpe:/a:the_cacti_group:cacti:0.8.6g</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0147</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:26.847-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-10T08:38:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22291" xml:lang="en">22291</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml" xml:lang="en">GLSA-200604-07</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1030" xml:lang="en">DSA-1030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1029" xml:lang="en">DSA-1029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2005-64/advisory/" xml:lang="en">http://secunia.com/secunia_research/2005-64/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19628" xml:lang="en">19628</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19591" xml:lang="en">19591</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19590" xml:lang="en">19590</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19555" xml:lang="en">19555</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18276" xml:lang="en">18276</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18260" xml:lang="en">18260</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18254" xml:lang="en">18254</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18233" xml:lang="en">18233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/17418" xml:lang="en">17418</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1332" xml:lang="en">ADV-2006-1332</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/1305" xml:lang="en">ADV-2006-1305</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0104" xml:lang="en">ADV-2006-0104</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0103" xml:lang="en">ADV-2006-0103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0102" xml:lang="en">ADV-2006-0102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0101" xml:lang="en">ADV-2006-0101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/430743/100/0/threaded" xml:lang="en">20060412 Simplog &lt;=0.9.2 multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/430448/100/0/threaded" xml:lang="en">20060409 PhpOpenChat 3.0.x ADODB Server.php "sql" SQL injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-1031" xml:lang="en">DSA-1031</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19600" xml:lang="en">19600</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18267" xml:lang="en">18267</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://retrogod.altervista.org/simplog_092_incl_xpl.html" xml:lang="en">http://retrogod.altervista.org/simplog_092_incl_xpl.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html" xml:lang="en">http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/1663" xml:lang="en">1663</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24052" xml:lang="en">adodb-tmssql-command-execution(24052)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19691" xml:lang="en">19691</vuln:reference>
    </vuln:references>
    <vuln:summary>Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP functions via the do parameter, which is saved in a variable that is then executed as a function, as demonstrated using phpinfo.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0148">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:netsarang:xlpd:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netsarang:xlpd:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0148</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:29.263-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-10T08:41:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16164" xml:lang="en">16164</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ipomonis.com/advisories/xlpd.txt" xml:lang="en">http://www.ipomonis.com/advisories/xlpd.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015444" xml:lang="en">1015444</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24041" xml:lang="en">xlpd-connection-dos(24041)</vuln:reference>
    </vuln:references>
    <vuln:summary>NetSarang Xlpd 2.1 allows remote attackers to cause a denial of service (crash) via a large number of connections from the same IP address.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0149">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:simpbook:simpbook:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:simpbook:simpbook:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0149</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:29.403-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-10T08:42:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015451" xml:lang="en">1015451</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041127.html" xml:lang="en">20060106 SimpBook "message" Remote Cross-Site Scripting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in SimpBook 1.0, with html_enable on (the default), allows remote attackers to inject arbitrary web script or HTML via the message field.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0150">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_carrigan:auth_ldap:1.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.3.3</vuln:product>
      <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.4.2</vuln:product>
      <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.3.0</vuln:product>
      <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.4.3</vuln:product>
      <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.2.1</vuln:product>
      <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.2.3</vuln:product>
      <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.3.2</vuln:product>
      <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.2.2</vuln:product>
      <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.2.4</vuln:product>
      <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.4.0</vuln:product>
      <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.3.4</vuln:product>
      <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.6.0</vuln:product>
      <vuln:product>cpe:/a:dave_carrigan:auth_ldap:1.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0150</vuln:cve-id>
    <vuln:discovered-datetime>2005-12-22T00:00:00.000-05:00</vuln:discovered-datetime>
    <vuln:published-datetime>2006-01-09T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-10T08:46:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-134"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:017" xml:lang="en">MDKSA-2006:017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16177" xml:lang="en">16177</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2006-0179.html" xml:lang="en">RHSA-2006:0179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-952" xml:lang="en">DSA-952</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18568" xml:lang="en">18568</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18412" xml:lang="en">18412</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18405" xml:lang="en">18405</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18382" xml:lang="en">18382</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24030" xml:lang="en">apache-authldap-format-string(24030)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0117" xml:lang="en">ADV-2006-0117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421286/100/0/threaded" xml:lang="en">20060109 Digital Armaments Security Advisory 01.09.2006: Apache auth_ldap module Multiple Format Strings Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.rudedog.org/auth_ldap/Changes.html" xml:lang="en">http://www.rudedog.org/auth_ldap/Changes.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitalarmaments.com/2006090173928420.html" xml:lang="en">http://www.digitalarmaments.com/2006090173928420.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015456" xml:lang="en">1015456</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0151">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p1"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p2"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p3"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p4"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p5"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p6"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p7"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.4_p1"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.4_p2"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.5_p1"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.5_p2"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.7_p5"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p1"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p12"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p2"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p5"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p7"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p8"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:4.1::ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:4.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.04::amd64"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.04::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.04::powerpc"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.10::amd64"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.10::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.10::powerpc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.5</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p7</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.7_p5</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.10::powerpc</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.6</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p6</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p3</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.5_p1</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.10::i386</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.4_p1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p9</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p5</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.5.9</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.5.6</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p5</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p7</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.5.8</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p8</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p12</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.4</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.10::amd64</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p4</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.7</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.04::i386</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.4_p2</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.04::amd64</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:4.1::ia64</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.5_p2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.2</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:4.1::ppc</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.5.7</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.04::powerpc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0151</vuln:cve-id>
    <vuln:published-datetime>2006-01-09T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-04-02T02:36:11.967-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-10T09:22:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18363" xml:lang="en">18363</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntulinux.org/support/documentation/usn/usn-235-2" xml:lang="en">USN-235-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16184" xml:lang="en">16184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18358" xml:lang="en">18358</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2006/0010" xml:lang="en">2006-0010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2006_02_sr.html" xml:lang="en">SUSE-SR:2006:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:159" xml:lang="en">MDKSA-2006:159</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-946" xml:lang="en">DSA-946</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.421822" xml:lang="en">SSA:2006-045-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/21692" xml:lang="en">21692</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19016" xml:lang="en">19016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18906" xml:lang="en">18906</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18558" xml:lang="en">18558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18549" xml:lang="en">18549</vuln:reference>
    </vuln:references>
    <vuln:summary>sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0152">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpchamber:phpchamber:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpchamber:phpchamber:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0152</vuln:cve-id>
    <vuln:published-datetime>2006-01-10T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:27.330-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-10T08:08:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0094" xml:lang="en">ADV-2006-0094</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16180" xml:lang="en">16180</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18360" xml:lang="en">18360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24029" xml:lang="en">phpchamber-searchresult-xss(24029)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22282" xml:lang="en">22282</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) in search_result.php in phpChamber 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the needle parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0153">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:427bb:fourtwosevenbb:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:427bb:fourtwosevenbb:2.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:427bb:fourtwosevenbb:2.2.1</vuln:product>
      <vuln:product>cpe:/a:427bb:fourtwosevenbb:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0153</vuln:cve-id>
    <vuln:published-datetime>2006-01-10T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:27.423-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-10T08:11:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0091" xml:lang="en">ADV-2006-0091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16178" xml:lang="en">16178</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded" xml:lang="en">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18354" xml:lang="en">18354</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/18/summary.html" xml:lang="en">http://evuln.com/vulns/18/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24038" xml:lang="en">427bb-scripts-security-bypass(24038)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22274" xml:lang="en">22274</vuln:reference>
    </vuln:references>
    <vuln:summary>427BB 2.2 and 2.2.1 verifies authentication credentials based on the username, authenticated, and usertype cookies, which allows remote attackers to bypass authentication by using a valid username and usertype and setting the authenticated cookie.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0154">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:427bb:fourtwosevenbb:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:427bb:fourtwosevenbb:2.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:427bb:fourtwosevenbb:2.2.1</vuln:product>
      <vuln:product>cpe:/a:427bb:fourtwosevenbb:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0154</vuln:cve-id>
    <vuln:published-datetime>2006-01-10T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:27.517-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-10T08:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0091" xml:lang="en">ADV-2006-0091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16169" xml:lang="en">16169</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded" xml:lang="en">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18354" xml:lang="en">18354</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/18/summary.html" xml:lang="en">http://evuln.com/vulns/18/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24039" xml:lang="en">427bb-showthread-sql-injection(24039)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22275" xml:lang="en">22275</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in showthread.php in 427BB 2.2 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the ForumID parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0155">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:427bb:fourtwosevenbb:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:427bb:fourtwosevenbb:2.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:427bb:fourtwosevenbb:2.2.1</vuln:product>
      <vuln:product>cpe:/a:427bb:fourtwosevenbb:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0155</vuln:cve-id>
    <vuln:published-datetime>2006-01-10T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:27.610-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-10T08:13:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0091" xml:lang="en">ADV-2006-0091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded" xml:lang="en">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18354" xml:lang="en">18354</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/18/summary.html" xml:lang="en">http://evuln.com/vulns/18/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24040" xml:lang="en">427bb-posts-xss(24040)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22276" xml:lang="en">22276</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in posts.php in 427BB 2.2 and 2.2.1 allows remote attackers to inject arbitrary Javascript via a new message with a url bbcode tag containing a javascript URI.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0156">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:foxrum:foxrum:4.0.4f"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:foxrum:foxrum:4.0.4f</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0156</vuln:cve-id>
    <vuln:published-datetime>2006-01-10T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:27.703-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-10T08:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0121" xml:lang="en">ADV-2006-0121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16172" xml:lang="en">16172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421277/100/0/threaded" xml:lang="en">20060109 [eVuln] Foxrum BBCode XSS Vulnerabilty</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18386" xml:lang="en">18386</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/20" xml:lang="en">http://evuln.com/vulns/20</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24043" xml:lang="en">foxrum-bbcode-xss(24043)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/325" xml:lang="en">325</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Foxrum 4.0.4f allows remote attackers to inject arbitrary Javascript via the javascript URI in bbcode url tags in (1) addpost1.php and (2) addtopic1.php.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0157">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:reamday_enterprises:magic_news_plus:1.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:reamday_enterprises:magic_news_plus:1.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0157</vuln:cve-id>
    <vuln:published-datetime>2006-01-10T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:30.717-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-10T08:18:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16182" xml:lang="en">16182</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://downloads.securityfocus.com/vulnerabilities/exploits/MagicNewsPlus-pw-change.pl" xml:lang="en">http://downloads.securityfocus.com/vulnerabilities/exploits/MagicNewsPlus-pw-change.pl</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18601" xml:lang="en">18601</vuln:reference>
    </vuln:references>
    <vuln:summary>settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password via a change action that specifies identical values for the passwd and admin_password parameters, then declares the new password string in the new_passwd and confirm_passwd parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0158">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cyberdoc:sitesuite_cms"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cyberdoc:sitesuite_cms</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0158</vuln:cve-id>
    <vuln:published-datetime>2006-01-10T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:27.860-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-10T08:21:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0038" xml:lang="en">ADV-2006-0038</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22205" xml:lang="en">22205</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18305" xml:lang="en">18305</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://osvdb.org/ref/22/22205-sitesuite.txt" xml:lang="en">http://osvdb.org/ref/22/22205-sitesuite.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in index.php in CyberDoc SiteSuite CMS allows remote attackers to execute arbitrary SQL commands via the page parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0159">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:javier_suarez_sanz:foro_domus:2.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:javier_suarez_sanz:foro_domus:2.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0159</vuln:cve-id>
    <vuln:published-datetime>2006-01-10T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-10T08:23:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24017" xml:lang="en">domus-escribir-sql-injection(24017)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0073" xml:lang="en">ADV-2006-0073</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22264" xml:lang="en">22264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18327" xml:lang="en">18327</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to execute arbitrary SQL commands via the email parameter.  NOTE: the provenance of this information is unknown, although it may be based on post-disclosure analysis of CVE-2006-0110; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0160">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:venom_board:venom_board:1.22"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:venom_board:venom_board:1.22</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0160</vuln:cve-id>
    <vuln:published-datetime>2006-01-10T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-08-08T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-10T08:26:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24046" xml:lang="en">venomboard-addpost-sql-injection(24046)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0122" xml:lang="en">ADV-2006-0122</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16176" xml:lang="en">16176</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22297" xml:lang="en">22297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/326" xml:lang="en">326</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18383" xml:lang="en">18383</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113683807903915&amp;w=2" xml:lang="en">20060109 [eVuln] Venom Board SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/21/summary.html" xml:lang="en">http://evuln.com/vulns/21/summary.html</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in add_post.php3 in Venom Board 1.22 allows remote attackers to execute arbitrary SQL commands via the (1) parent, (2) root, and (3) topic_id parameters to post.php3.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0161">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0161</vuln:cve-id>
    <vuln:published-datetime>2006-01-10T14:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:28.097-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T08:51:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1534" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1534" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101933-1" xml:lang="en">101933</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0113" xml:lang="en">ADV-2006-0113</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015455" xml:lang="en">1015455</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19087" xml:lang="en">19087</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18371" xml:lang="en">18371</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1534" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1534" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors.  NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004-0780.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0162">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:."/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.51"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.52"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.53"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.54"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.60"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.65"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.67"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.68"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.68.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.70"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.75.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80_rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80_rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.81"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.82"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.83"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.84"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.84_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.84_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.85"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.85.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.86"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.86.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.86.2"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.87"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.87.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.84_rc1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80_rc2</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.70</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.52</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.84</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.60</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.65</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.54</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.75.1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.67</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.85.1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.51</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.68.1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.83</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.86</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.84_rc2</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.81</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.85</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80_rc3</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80_rc1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.68</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.53</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.86.2</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:.</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.86.1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80_rc4</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.82</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.87</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.87.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0162</vuln:cve-id>
    <vuln:published-datetime>2006-01-10T14:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:28.220-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-11T08:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/385908" xml:lang="en">VU#385908</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16191" xml:lang="en">16191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18379" xml:lang="en">18379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0116" xml:lang="en">ADV-2006-0116</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.clamav.net/doc/0.88/ChangeLog" xml:lang="en">http://www.clamav.net/doc/0.88/ChangeLog</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24047" xml:lang="en">clamav-libclamav-upx-bo(24047)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-06-001.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-06-001.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2006/0002/" xml:lang="en">2006-0002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22318" xml:lang="en">22318</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:016" xml:lang="en">MDKSA-2006:016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200601-07.xml" xml:lang="en">GLSA-200601-07</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-947" xml:lang="en">DSA-947</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015457" xml:lang="en">1015457</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/342" xml:lang="en">342</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18548" xml:lang="en">18548</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18478" xml:lang="en">18478</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18463" xml:lang="en">18463</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18453" xml:lang="en">18453</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041325.html" xml:lang="en">20060112 ZDI-06-001: Clam AntiVirus UPX Unpacking Code Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in libclamav/upx.c in Clam Antivirus (ClamAV) before 0.88 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted UPX files.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0163">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke_ev:7.7_r1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke_ev:7.7_r1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0163</vuln:cve-id>
    <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:28.313-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T08:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/44978" xml:lang="en">phpnukeev-search-sql-injection(44978)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0120" xml:lang="en">ADV-2006-0120</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16186" xml:lang="en">16186</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22316" xml:lang="en">22316</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18394" xml:lang="en">18394</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://lostmon.blogspot.com/2006/01/phpnuke-ev-77-search-module-query.html" xml:lang="en">http://lostmon.blogspot.com/2006/01/phpnuke-ev-77-search-module-query.html</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in the search module (modules/Search/index.php) of PHPNuke EV 7.7 -R1 allows remote attackers to execute arbitrary SQL commands via the query parameter, which is used by the search field.  NOTE: This is a different vulnerability than CVE-2005-3792.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0164">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:woah-projekt:phgstats:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:woah-projekt:phgstats:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:woah-projekt:phgstats:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:woah-projekt:phgstats:0.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:woah-projekt:phgstats:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:woah-projekt:phgstats:0.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:woah-projekt:phgstats:0.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:woah-projekt:phgstats:0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:woah-projekt:phgstats:0.2</vuln:product>
      <vuln:product>cpe:/a:woah-projekt:phgstats:0.1</vuln:product>
      <vuln:product>cpe:/a:woah-projekt:phgstats:0.4.1</vuln:product>
      <vuln:product>cpe:/a:woah-projekt:phgstats:0.3.1</vuln:product>
      <vuln:product>cpe:/a:woah-projekt:phgstats:0.4</vuln:product>
      <vuln:product>cpe:/a:woah-projekt:phgstats:0.5</vuln:product>
      <vuln:product>cpe:/a:woah-projekt:phgstats:0.4.2</vuln:product>
      <vuln:product>cpe:/a:woah-projekt:phgstats:0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0164</vuln:cve-id>
    <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:28.407-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T08:11:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=384232" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=384232</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18346" xml:lang="en">18346</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0123" xml:lang="en">ADV-2006-0123</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24062" xml:lang="en">phgstats-php-file-include(24062)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/17469" xml:lang="en">17469</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22302" xml:lang="en">22302</vuln:reference>
    </vuln:references>
    <vuln:summary>phgstats.inc.php in phgstats before 0.5.1, if register_globals is enabled, allows remote attackers to include arbitrary files and execute arbitrary PHP code by modifying the PHGDIR variable.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0165">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:5.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.2.10_gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.2.11_gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.3.0_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.4.0_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.0_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.1_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.2_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.3_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.4_gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.5_gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.6_gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.6.0_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.6.1_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.6.2_gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.6.3_gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.6.4_gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.0_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.1_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.2_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.3_gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.4_gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.5_gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.6_gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.7_gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.8_gamma"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.8.1_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.8.2_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.8.3_gamma"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.6_gamma</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.4.0_beta</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.8.3_gamma</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.1_beta</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.6.1_beta</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.6.5</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.4_gamma</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.1_beta</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:5.5.8</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.5_gamma</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.2.11_gamma</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.3.0_beta</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.8_gamma</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.6_gamma</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.2_beta</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.2_beta</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.6.4_gamma</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.2.10_gamma</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.6.3_gamma</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.0_beta</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.6.0_beta</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.3_beta</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.4_gamma</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.5_gamma</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.8.1_beta</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.3_gamma</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.6.2_gamma</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.8.2_beta</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.7_gamma</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.0_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0165</vuln:cve-id>
    <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:28.500-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T08:13:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=384153&amp;group_id=51417" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=384153&amp;group_id=51417</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18372" xml:lang="en">18372</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0126" xml:lang="en">ADV-2006-0126</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1395371&amp;group_id=51417&amp;atid=463213" xml:lang="en">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1395371&amp;group_id=51417&amp;atid=463213</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24053" xml:lang="en">webgui-forms-xss(24053)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the DataForm Entries functionality in Plain Black WebGUI before 6.8.4 (gamma) allows remote attackers to inject arbitrary Javascript via the (1) url and (2) name field of the default email form.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0166">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_system_works:2005"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_system_works:2005_premier"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_system_works:2006"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_system_works:2006_premier"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:norton_system_works:2005_premier</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_system_works:2005</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_system_works:2006_premier</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_system_works:2006</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0166</vuln:cve-id>
    <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:28.597-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T15:47:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015462" xml:lang="en">1015462</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://securityresponse.symantec.com/avcenter/security/Content/2006.01.10.html" xml:lang="en">http://securityresponse.symantec.com/avcenter/security/Content/2006.01.10.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18402" xml:lang="en">18402</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24061" xml:lang="en">systemworks-nprotect-hidden(24061)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0143" xml:lang="en">ADV-2006-0143</vuln:reference>
    </vuln:references>
    <vuln:summary>Symantec Norton SystemWorks and SystemWorks Premier 2005 and 2006 stores temporary copies of files in the Norton Protected Recycle Bin NProtect directory, which is hidden from the FindFirst and FindNext Windows APIs and allows remote attackers to hide arbitrary files from virus scanners and other products.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0167">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:myphpim:myphpim:01.05"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:myphpim:myphpim:01.05</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0167</vuln:cve-id>
    <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:28.703-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T12:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24075" xml:lang="en">myphpim-login-sql-injection(24075)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24066" xml:lang="en">myphpim-calendar-sql-injection(24066)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0147" xml:lang="en">ADV-2006-0147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16210" xml:lang="en">16210</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421863/100/0/threaded" xml:lang="en">20060111 [eVuln] MyPhPim Multiple SQL Injection and XSS Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22325" xml:lang="en">22325</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22324" xml:lang="en">22324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18399" xml:lang="en">18399</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/22/summary.html" xml:lang="en">http://evuln.com/vulns/22/summary.html</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in MyPhPim 01.05 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter in calendar.php3 and the (2) password field on the login page.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0168">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:myphpim:myphpim:01.05"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:myphpim:myphpim:01.05</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0168</vuln:cve-id>
    <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:28.813-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T12:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24071" xml:lang="en">myphpim-todo-xss(24071)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0147" xml:lang="en">ADV-2006-0147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16210" xml:lang="en">16210</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421863/100/0/threaded" xml:lang="en">20060111 [eVuln] MyPhPim Multiple SQL Injection and XSS Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22326" xml:lang="en">22326</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18399" xml:lang="en">18399</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/22/summary.html" xml:lang="en">http://evuln.com/vulns/22/summary.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in MyPhPim 01.05 allows remote attackers to inject arbitrary web script or HTML via the description field on the "Create New todo" page.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0169">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:myphpim:myphpim:01.05"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:myphpim:myphpim:01.05</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0169</vuln:cve-id>
    <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:28.907-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-05-05T08:55:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24070" xml:lang="en">myphpim-addresses-file-upload(24070)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0147" xml:lang="en">ADV-2006-0147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16208" xml:lang="en">16208</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421626/100/0/threaded" xml:lang="en">20060111 [eVuln] MyPhPim Arbitrary File Upload</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18399" xml:lang="en">18399</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/23/summary.html" xml:lang="en">http://evuln.com/vulns/23/summary.html</vuln:reference>
    </vuln:references>
    <vuln:summary>addresses.php3 in MyPhPim 01.05 does not restrict uploaded files, which allows remote attackers to execute arbitrary PHP code via the pdbfile variable, then directly accessing those files from the uploads directory.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0170">
    <vuln:cve-id>CVE-2006-0170</vuln:cve-id>
    <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:56:39.307-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0035.  Reason: This candidate is a duplicate of CVE-2006-0035.  Notes: All CVE users should reference CVE-2006-0035 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0171">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:orjinweb:orjinweb_e-commerce"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:orjinweb:orjinweb_e-commerce</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0171</vuln:cve-id>
    <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:32.887-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T12:22:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16199" xml:lang="en">16199</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421312/100/0/threaded" xml:lang="en">20060106 Orjinweb E-commerce</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24097" xml:lang="en">orjinweb-url-file-include(24097)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22387" xml:lang="en">22387</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file include vulnerability in index.php in OrjinWeb E-commerce allows remote attackers to execute arbitrary code via a URL in the page parameter.  NOTE: it is not clear, but OrjinWeb might be an application service, in which case it should not be included in CVE.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0172">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hummingbird:enterprise_collaboration:5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:hummingbird:enterprise_collaboration:5.21"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hummingbird:enterprise_collaboration:5.21</vuln:product>
      <vuln:product>cpe:/a:hummingbird:enterprise_collaboration:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0172</vuln:cve-id>
    <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:29.033-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>3.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication approximated="true">SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T12:28:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0145" xml:lang="en">ADV-2006-0145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16195" xml:lang="en">16195</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421392/100/0/threaded" xml:lang="en">20060110 Multiple Vulnerabilities in Hummingbird Collaboration</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securenetwork.it/advisories/sn-2006-01.html" xml:lang="en">http://www.securenetwork.it/advisories/sn-2006-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18411" xml:lang="en">18411</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24067" xml:lang="en">hummingbird-enterprise-xss(24067)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the file manager utility in Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML in an uploaded page, which is published without a check for hostile scripting.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0173">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hummingbird:enterprise_collaboration:5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:hummingbird:enterprise_collaboration:5.21"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hummingbird:enterprise_collaboration:5.21</vuln:product>
      <vuln:product>cpe:/a:hummingbird:enterprise_collaboration:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0173</vuln:cve-id>
    <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:29.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication approximated="true">SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T12:32:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0145" xml:lang="en">ADV-2006-0145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16195" xml:lang="en">16195</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421392/100/0/threaded" xml:lang="en">20060110 Multiple Vulnerabilities in Hummingbird Collaboration</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securenetwork.it/advisories/sn-2006-01.html" xml:lang="en">http://www.securenetwork.it/advisories/sn-2006-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18411" xml:lang="en">18411</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24068" xml:lang="en">hummingbird-enterprise-file-download(24068)</vuln:reference>
    </vuln:references>
    <vuln:summary>Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a file via modified doc_ext and id parameters, which might trick a user into downloading dangerous or unexpected content.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0174">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hummingbird:collaboration:5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:hummingbird:enterprise_collaboration:5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:hummingbird:collaboration:5.21"/>
        <cpe-lang:fact-ref name="cpe:/a:hummingbird:enterprise_collaboration:5.21"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hummingbird:collaboration:5.2</vuln:product>
      <vuln:product>cpe:/a:hummingbird:enterprise_collaboration:5.21</vuln:product>
      <vuln:product>cpe:/a:hummingbird:enterprise_collaboration:5.2</vuln:product>
      <vuln:product>cpe:/a:hummingbird:collaboration:5.21</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0174</vuln:cve-id>
    <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:29.237-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication approximated="true">SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T12:34:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0145" xml:lang="en">ADV-2006-0145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16195" xml:lang="en">16195</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421392/100/0/threaded" xml:lang="en">20060110 Multiple Vulnerabilities in Hummingbird Collaboration</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securenetwork.it/advisories/sn-2006-01.html" xml:lang="en">http://www.securenetwork.it/advisories/sn-2006-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18411" xml:lang="en">18411</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24069" xml:lang="en">hummingbird-enterprise-information-disclosure(24069)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/328" xml:lang="en">328</vuln:reference>
    </vuln:references>
    <vuln:summary>Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumerations of valid parameter values) via a direct request to hc, which reveals the information in an error message or a cookie.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0175">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:webwiz:web_wiz_forums:6.34"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webwiz:web_wiz_forums:6.34</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0175</vuln:cve-id>
    <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-01-03T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T13:09:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16196" xml:lang="en">16196</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24048" xml:lang="en">webwizforums-searchform-xss(24048)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421615/100/0/threaded" xml:lang="en">20060111 Advisory:XSS vulnerability on WebWiz Forums &lt;= 6.34(search_form.asp)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22398" xml:lang="en">22398</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0299.html" xml:lang="en">20060109 Advisory:XSS vulnerability on WebWiz Forums &lt;= 6.34 (search_form.asp)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in search_form.asp in Web Wiz Forums 6.34 allows remote attackers to inject arbitrary web script or HTML via the search parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0176">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xmame:xmame:0.102"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xmame:xmame:0.102</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0176</vuln:cve-id>
    <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:33.683-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T13:19:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16203" xml:lang="en">16203</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421849/100/0/threaded" xml:lang="en">20060110 mysec.org Security Advisory : Xmame buffer overflow, with a possibility of privilege escalation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0353.html" xml:lang="en">20060110 mysec.org Security Advisory : Xmame buffer overflow, with a possibility of privilege escalation.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24102" xml:lang="en">xmame-multiple-parameters-bo(24102)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://x.mame.net/changes-unix.html" xml:lang="en">http://x.mame.net/changes-unix.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in certain functions in src/fileio.c and src/unix/fileio.c in xmame before 11 January 2006 may allow local users to gain privileges via a long (1) -lang, (2) -ctrlr, (3) -pb, or (4) -rec argument on many operating systems, and via a long (5) -jdev argument on Ubuntu Linux.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0177">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:9.0.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cray:unicos:9.0.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0177</vuln:cve-id>
    <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:33.840-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T13:28:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16205" xml:lang="en">16205</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0343.html" xml:lang="en">20060110 SUID root overflows in UNICOS and partial shellcode</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24276" xml:lang="en">unicos-command-line-bo(24276)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Cray UNICOS 9.0.2.2 might allow local users to gain privileges by (1) invoking /usr/bin/script with a long command line argument or (2) setting the -c option of /etc/nu to the name of a file containing a long line.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0178">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:9.0.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cray:unicos:9.0.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0178</vuln:cve-id>
    <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:33.980-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T13:34:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16205" xml:lang="en">16205</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0343.html" xml:lang="en">20060110 SUID root overflows in UNICOS and partial shellcode</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24277" xml:lang="en">unicos-ftp-format-string(24277)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in /bin/ftp in UNICOS 9.0.2.2 allows local users to have an unknown impact via format string specifiers in the quote command.  NOTE: because the program is not setuid and not normally called from remote programs, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0179">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:cisco:ip_phone_7940"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:ip_phone_7940</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0179</vuln:cve-id>
    <vuln:published-datetime>2006-01-11T16:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T13:41:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015488" xml:lang="en">1015488</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18479" xml:lang="en">18479</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24117" xml:lang="en">cisco-ipphone-synflood-dos(24117)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0202" xml:lang="en">ADV-2006-0202</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16200" xml:lang="en">16200</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22469" xml:lang="en">22469</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-response-20060113-ip-phones.shtml" xml:lang="en">20060113 Response to Cisco IP Phone 7940 DoS Exploit posted on milw0rm.com</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://downloads.securityfocus.com/vulnerabilities/exploits/cisco_ip7940_dos.pl" xml:lang="en">http://downloads.securityfocus.com/vulnerabilities/exploits/cisco_ip7940_dos.pl</vuln:reference>
    </vuln:references>
    <vuln:summary>The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary ports, as demonstrated to port 80.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0180">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:calogic:calogic_calendars:1.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:calogic:calogic_calendars:1.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0180</vuln:cve-id>
    <vuln:published-datetime>2006-01-12T01:02:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:31.987-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T07:27:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0149" xml:lang="en">ADV-2006-0149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16206" xml:lang="en">16206</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18417" xml:lang="en">18417</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/24/summary.html" xml:lang="en">http://evuln.com/vulns/24/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24077" xml:lang="en">calogic-newevent-xss(24077)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/422163/100/0/threaded" xml:lang="en">20060116 [eVuln] CaLogic Calendars Multiple XSS Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22322" xml:lang="en">22322</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the Title field on the "Adding New Event" page, and possibly other vectors, involving iframe tags.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0181">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:cisco:cs-mars:4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:cs-mars:4.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:cs-mars:4.1.2</vuln:product>
      <vuln:product>cpe:/h:cisco:cs-mars:4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0181</vuln:cve-id>
    <vuln:published-datetime>2006-01-12T01:02:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:32.063-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T07:37:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16211" xml:lang="en">16211</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20060111-mars.shtml" xml:lang="en">20060111 Default Administrative Password in Cisco Security Monitoring, Analysis and Response System (CS-MARS)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0154" xml:lang="en">ADV-2006-0154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24065" xml:lang="en">cisco-csmars-default-password(24065)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22346" xml:lang="en">22346</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015471" xml:lang="en">1015471</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/335" xml:lang="en">335</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18424" xml:lang="en">18424</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.1.3 has an undocumented administrative account with a default password, which allows local users to gain privileges via the expert command.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0182">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:acal:calendar_project:2.2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:acal:calendar_project:2.2.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0182</vuln:cve-id>
    <vuln:published-datetime>2006-01-12T01:02:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:32.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T07:40:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0152" xml:lang="en">ADV-2006-0152</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/25/summary.html" xml:lang="en">http://evuln.com/vulns/25/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24104" xml:lang="en">acal-login-auth-bypass(24104)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421744/100/0/threaded" xml:lang="en">20060112 [eVuln] ACal Authentication Bypass &amp; PHP Code Insertion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22344" xml:lang="en">22344</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/343" xml:lang="en">343</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18432" xml:lang="en">18432</vuln:reference>
    </vuln:references>
    <vuln:summary>login.php in ACal Calendar Project 2.2.5 allows remote attackers to bypass authentication by setting the ACalAuthenticate cookie variable to "inside".</vuln:summary>
  </entry>
  <entry id="CVE-2006-0183">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:acal:calendar_project:2.2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:acal:calendar_project:2.2.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0183</vuln:cve-id>
    <vuln:published-datetime>2006-01-12T01:02:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:32.187-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication approximated="true">SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T07:41:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0152" xml:lang="en">ADV-2006-0152</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/25/summary.html" xml:lang="en">http://evuln.com/vulns/25/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24107" xml:lang="en">acal-header-footer-code-execute(24107)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421744/100/0/threaded" xml:lang="en">20060112 [eVuln] ACal Authentication Bypass &amp; PHP Code Insertion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22345" xml:lang="en">22345</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/343" xml:lang="en">343</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18432" xml:lang="en">18432</vuln:reference>
    </vuln:references>
    <vuln:summary>Direct static code injection vulnerability in edit.php in ACal Calendar Project 2.2.5 allows authenticated users to execute arbitrary PHP code via (1) the edit=header value, which modifies header.php, or (2) the edit=footer value, which modifies footer.php.  NOTE: this issue might be resultant from the poor authentication as identified by CVE-2006-0182.  Since the design of the product allows the administrator to edit the code, perhaps this issue should not be included in CVE, except as a consequence of CVE-2006-0182.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0184">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mainenet_enterprises:asptopsites"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mainenet_enterprises:asptopsites</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0184</vuln:cve-id>
    <vuln:published-datetime>2006-01-12T01:02:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:32.283-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T07:42:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0146" xml:lang="en">ADV-2006-0146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.exploitlabs.com/files/advisories/EXPL-A-2006-001-asptopsites.txt" xml:lang="en">http://www.exploitlabs.com/files/advisories/EXPL-A-2006-001-asptopsites.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18408" xml:lang="en">18408</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24072" xml:lang="en">asptopsites-goto-sql-injection(24072)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22330" xml:lang="en">22330</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0351.html" xml:lang="en">20060110 AspTopSites SQL injection</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in AspTopSites allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to goto.asp or (2) password parameter to includeloginuser.asp.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0185">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php-nuke:news_module"/>
        <cpe-lang:fact-ref name="cpe:/a:php-nuke:pool_module"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php-nuke:news_module</vuln:product>
      <vuln:product>cpe:/a:php-nuke:pool_module</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0185</vuln:cve-id>
    <vuln:published-datetime>2006-01-12T01:02:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:32.347-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T07:43:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0125" xml:lang="en">ADV-2006-0125</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16192" xml:lang="en">16192</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/421322" xml:lang="en">20060107 Php-Nuke Pool and News Module IMG Tag Cross Site</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18374" xml:lang="en">18374</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0186">
    <vuln:cve-id>CVE-2006-0186</vuln:cve-id>
    <vuln:published-datetime>2006-01-12T01:02:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T15:56:42.383-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-4500.  Reason: This candidate is a duplicate of CVE-2005-4500.  Notes: All CVE users should reference CVE-2005-4500 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0187">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_studio_.net:2005"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:visual_studio_.net:2005</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0187</vuln:cve-id>
    <vuln:published-datetime>2006-01-12T01:02:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:32.453-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-12T07:55:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0151" xml:lang="en">ADV-2006-0151</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16225" xml:lang="en">16225</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421943/100/0/threaded" xml:lang="en">20060113 Visual Studio Remote Code Execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18409" xml:lang="en">18409</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24116" xml:lang="en">visualstudio-usercontrol-code-execution(24116)</vuln:reference>
    </vuln:references>
    <vuln:summary>By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the user into opening a malicious Visual Studio project file.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0188">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3_r3"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3a"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.4_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.6_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4_rc1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.6_rc1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3a</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.4</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4_rc1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3_r3</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.4_rc1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3_rc1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.2</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0188</vuln:cve-id>
    <vuln:published-datetime>2006-02-23T19:02:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:32.627-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-02-24T08:46:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10419" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10419" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24847" xml:lang="en">squirrelmail-webmail-xss(24847)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0689" xml:lang="en">ADV-2006-0689</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squirrelmail.org/security/issue/2006-02-01" xml:lang="en">http://www.squirrelmail.org/security/issue/2006-02-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16756" xml:lang="en">16756</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015662" xml:lang="en">1015662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18985" xml:lang="en">18985</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2006-0283.html" xml:lang="en">RHSA-2006:0283</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00004.html" xml:lang="en">FEDORA-2006-133</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2006_05_sr.html" xml:lang="en">SUSE-SR:2006:005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:049" xml:lang="en">MDKSA-2006:049</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200603-09.xml" xml:lang="en">GLSA-200603-09</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-988" xml:lang="en">DSA-988</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20210" xml:lang="en">20210</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19960" xml:lang="en">19960</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19205" xml:lang="en">19205</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19176" xml:lang="en">19176</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19131" xml:lang="en">19131</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19130" xml:lang="en">19130</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" xml:lang="en">20060501-01-U</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10419" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10419" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>webmail.php in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary web pages into the right frame via a URL in the right_frame parameter.  NOTE: this has been called a cross-site scripting (XSS) issue, but it is different than what is normally identified as XSS.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0189">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:estara:softphone:3.0.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:estara:softphone:3.0.1.46"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:estara:softphone:3.0.1.46</vuln:product>
      <vuln:product>cpe:/a:estara:softphone:3.0.1.14</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0189</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:32.720-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-13T07:39:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24090" xml:lang="en">estara-sip-sdp-bo(24090)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0167" xml:lang="en">ADV-2006-0167</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16213" xml:lang="en">16213</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421596/100/0/threaded" xml:lang="en">20060111 eStara Softphone SIP stack Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015481" xml:lang="en">1015481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18410" xml:lang="en">18410</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22348" xml:lang="en">22348</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in eStara Softphone 3.0.1.14 through 3.0.1.46 allows remote attackers to execute arbitrary code via a long attribute (aka "a") field in the SDP data of a SIP packet on UDP port 5060.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0190">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:10.0::sparc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0190</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:32.830-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-13T07:44:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:702" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:702" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102066-1" xml:lang="en">102066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18421" xml:lang="en">18421</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0165" xml:lang="en">ADV-2006-0165</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24084" xml:lang="en">solaris-unspecified-root-access(24084)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16224" xml:lang="en">16224</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015478" xml:lang="en">1015478</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19087" xml:lang="en">19087</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:702" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:702" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Sun Solaris 9 and 10 for the x86 platform allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors, possibly involving functions from the mm driver.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0191">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10.0::sparc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:10.0::sparc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0191</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:32.923-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-13T07:45:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1608" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1608" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102108-1" xml:lang="en">102108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18420" xml:lang="en">18420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0166" xml:lang="en">ADV-2006-0166</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24085" xml:lang="en">solaris-find-proc-dos(24085)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16222" xml:lang="en">16222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22347" xml:lang="en">22347</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015479" xml:lang="en">1015479</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19087" xml:lang="en">19087</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1608" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1608" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Sun Solaris 10 allows local users to cause a denial of service (null dereference) via unspecified vectors involving the use of the find command on the "/proc" filesystem. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2005-3250.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0192">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:philip_loftin:aspsurvey:1.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:philip_loftin:aspsurvey:1.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0192</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-08-05T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-13T07:49:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24087" xml:lang="en">aspsurvey-loginvalidate-sql-injection(24087)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0164" xml:lang="en">ADV-2006-0164</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16496" xml:lang="en">16496</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/423949/100/0/threaded" xml:lang="en">20060204 sql injection in ASP Survey</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22342" xml:lang="en">22342</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/414" xml:lang="en">414</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18422" xml:lang="en">18422</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in Login_Validate.asp in ASPSurvey 1.10 allows remote attackers to execute arbitrary SQL commands via the Password parameter to login.asp.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0193">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.1_patch_1"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.1_patch_2"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.1_patch_3"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.1_patch_4"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.1_patch_5"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.1_patch_6"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.1_patch_7"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.2_beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.2_beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.2_beta_3"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.2_patch_1"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.2_patch_2"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.2_patch_3"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.2_patch_4"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.2_patch_5"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.2_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.2_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.3_beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.3_beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.3_patch_1"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.3_patch_2"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.3_patch_3"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.3_patch_4"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.3_patch_5"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.3_patch_6"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.3_patch_7"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.3_patch_8"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.3_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:positive_software:h-sphere:2.4.3_rc2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.2_patch_2</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.1_patch_7</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.2</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.1</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.3_beta_2</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.3_patch_8</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.2_patch_4</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.1_patch_6</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.3_patch_1</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.3_patch_2</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.3_patch_4</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.2_patch_3</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.3_rc2</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.2_rc2</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.1_patch_3</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.1_patch_1</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.3_rc1</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.3_patch_3</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.3</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.2_patch_5</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.2_beta_3</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.1_patch_5</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.2_beta_2</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.1_patch_4</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.2_beta_1</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.3_patch_6</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.3_patch_5</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.3_beta_1</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.1_patch_2</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.2_rc1</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.2_patch_1</vuln:product>
      <vuln:product>cpe:/a:positive_software:h-sphere:2.4.3_patch_7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0193</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:33.110-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-13T09:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421704/100/0/threaded" xml:lang="en">20060112 H-Sphere Security Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0172" xml:lang="en">ADV-2006-0172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.psoft.net/HSdocumentation/versions/?v=all&amp;p=r" xml:lang="en">http://www.psoft.net/HSdocumentation/versions/?v=all&amp;p=r</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24096" xml:lang="en">hsphere-login-xss(24096)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.psoft.net/HSdocumentation/versions/index.php?v=243p9&amp;p=r" xml:lang="en">http://www.psoft.net/HSdocumentation/versions/index.php?v=243p9&amp;p=r</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22372" xml:lang="en">22372</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18447" xml:lang="en">18447</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the Hosting Control Panel (psoft.hsphere.CP) in Positive Software H-Sphere 2.4.3 Patch 8 and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter in a login action.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0194">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:fog_creek_software:fogbugz:4.029"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fog_creek_software:fogbugz:4.029</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0194</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T06:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:33.203-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-13T09:10:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16216" xml:lang="en">16216</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0174" xml:lang="en">ADV-2006-0174</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421729/100/0/threaded" xml:lang="en">20060112 FogBugz Cross Site Scripting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.fogcreek.com/FogBugz/KB/releaseNotes/WhatsNewInFogBugz4.0.33.html" xml:lang="en">http://www.fogcreek.com/FogBugz/KB/releaseNotes/WhatsNewInFogBugz4.0.33.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24103" xml:lang="en">fogbugz-login-xss(24103)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22370" xml:lang="en">22370</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18443" xml:lang="en">18443</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in default.asp in FogBugz 4.029, and other versions before 4.0.33, allows remote attackers to inject arbitrary web script or HTML via the dest parameter in the pgLogon page.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0195">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3_r3"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3a"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.4_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.6_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4_rc1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.6_rc1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3a</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.4</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4_rc1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3_r3</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.4_rc1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3_rc1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.2</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0195</vuln:cve-id>
    <vuln:published-datetime>2006-02-23T19:02:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:33.297-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-02-24T09:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9548" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9548" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24848" xml:lang="en">squirrelmail-magichtml-xss(24848)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0689" xml:lang="en">ADV-2006-0689</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squirrelmail.org/security/issue/2006-02-10" xml:lang="en">http://www.squirrelmail.org/security/issue/2006-02-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16756" xml:lang="en">16756</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015662" xml:lang="en">1015662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18985" xml:lang="en">18985</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2006-0283.html" xml:lang="en">RHSA-2006:0283</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00004.html" xml:lang="en">FEDORA-2006-133</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2006_05_sr.html" xml:lang="en">SUSE-SR:2006:005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:049" xml:lang="en">MDKSA-2006:049</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200603-09.xml" xml:lang="en">GLSA-200603-09</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2006/dsa-988" xml:lang="en">DSA-988</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20210" xml:lang="en">20210</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19960" xml:lang="en">19960</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19205" xml:lang="en">19205</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19176" xml:lang="en">19176</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19131" xml:lang="en">19131</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19130" xml:lang="en">19130</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" xml:lang="en">20060501-01-U</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9548" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9548" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Interpretation conflict in the MagicHTML filter in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via style sheet specifiers with invalid (1) "/*" and "*/" comments, or (2) a newline in a "url" specifier, which is processed by certain web browsers including Internet Explorer.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0196">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:serial_line_sniffer:serial_line_sniffer:0.4.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:serial_line_sniffer:serial_line_sniffer:0.4.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0196</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:33.487-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-17T09:24:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24082" xml:lang="en">slsnif-home-bo(24082)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0212" xml:lang="en">ADV-2006-0212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421583/100/0/threaded" xml:lang="en">20060111 Serial Line Sniffer 0.4.4 Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://shellcoders.com/sintigan/slsnif-ploit.pl" xml:lang="en">http://shellcoders.com/sintigan/slsnif-ploit.pl</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18497" xml:lang="en">18497</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Serial line sniffer (aka slsnif) 0.4.4 allows local users to gain privileges via a long value of the HOME environment variable, possibly because of a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0197">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:x.org:x.org:6.8.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:x.org:x.org:6.8.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0197</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:36.840-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-17T09:31:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421256/100/0/threaded" xml:lang="en">20060108 xorg server 6.8.2 and below on 64bit arch</vuln:reference>
    </vuln:references>
    <vuln:summary>The XClientMessageEvent struct used in certain components of X.Org 6.8.2 and earlier, possibly including (1) the X server and (2) Xlib, uses a "long" specifier for elements of the l array, which results in inconsistent sizes in the struct on 32-bit versus 64-bit platforms, and might allow attackers to cause a denial of service (application crash) and possibly conduct other attacks.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0198">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xoops:xoops_pool_module"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xoops:xoops_pool_module</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0198</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:36.980-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-17T09:33:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.xoops.org/modules/newbb/viewtopic.php?topic_id=45637&amp;forum=2&amp;post_id=200481" xml:lang="en">http://www.xoops.org/modules/newbb/viewtopic.php?topic_id=45637&amp;forum=2&amp;post_id=200481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16189" xml:lang="en">16189</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421325/100/0/threaded" xml:lang="en">20060107 Xoops Pool Module IMG Tag Cross Site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24091" xml:lang="en">xoops-pool-imagetag-xss(24091)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in a certain module, possibly poll or Pool, for XOOPS allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element in a comment.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0199">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mini-nuke:cms_system:1.8.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mini-nuke:cms_system:1.8.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0199</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-08-05T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-05-02T10:47:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24098" xml:lang="en">mininuke-news-sql-injection(24098)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0173" xml:lang="en">ADV-2006-0173</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421727/100/0/threaded" xml:lang="en">20060113 Advisory: MiniNuke CMS System &lt;= 1.8.2 (news.asp) SQL Injectionvulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22384" xml:lang="en">22384</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nukedx.com/?viewdoc=7" xml:lang="en">http://www.nukedx.com/?viewdoc=7</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/340" xml:lang="en">340</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18439" xml:lang="en">18439</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0439.html" xml:lang="en">20060112 Advisory: MiniNuke CMS System &lt;= 1.8.2 (news.asp) SQL Injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0200">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:5.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0200</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:33.813-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-17T09:35:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-134"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24095" xml:lang="en">php-extmysqli-format-string(24095)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16219" xml:lang="en">16219</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/release_5_1_2.php" xml:lang="en">http://www.php.net/release_5_1_2.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18431" xml:lang="en">18431</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0369" xml:lang="en">ADV-2006-0369</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0177" xml:lang="en">ADV-2006-0177</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421705/100/0/threaded" xml:lang="en">20060112 Advisory 02/2006: PHP ext/mysqli Format String Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hardened-php.net/advisory_022006.113.html" xml:lang="en">http://www.hardened-php.net/advisory_022006.113.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015485" xml:lang="en">1015485</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/337" xml:lang="en">337</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0201">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:paypal:php_toolkit:0.50"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:paypal:php_toolkit:0.50</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0201</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:34.347-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-17T09:41:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0183" xml:lang="en">ADV-2006-0183</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uinc.ru/articles/vuln/ptpaypal050.shtml" xml:lang="en">http://www.uinc.ru/articles/vuln/ptpaypal050.shtml</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16218" xml:lang="en">16218</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/421739" xml:lang="en">20060112 Multiple PHP Toolkit for PayPal Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18444" xml:lang="en">18444</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22378" xml:lang="en">22378</vuln:reference>
    </vuln:references>
    <vuln:summary>Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50, and possibly earlier versions, allows remote attackers to enter false payment entries into the log file via HTTP POST requests to ipn_success.php.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0202">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:paypal:php_toolkit:0.50"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:paypal:php_toolkit:0.50</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0202</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:34.437-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>3.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-17T09:43:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0183" xml:lang="en">ADV-2006-0183</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.uinc.ru/articles/vuln/ptpaypal050.shtml" xml:lang="en">http://www.uinc.ru/articles/vuln/ptpaypal050.shtml</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16218" xml:lang="en">16218</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/421739" xml:lang="en">20060112 Multiple PHP Toolkit for PayPal Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18444" xml:lang="en">18444</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22379" xml:lang="en">22379</vuln:reference>
    </vuln:references>
    <vuln:summary>Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50 and possibly earlier has (1) world-readable permissions for ipn/logs/ipn_success.txt, which allows local users to view sensitive information (payment data), and (2) world-writable permissions for ipn/logs, which allows local users to delete or replace payment data.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0203">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mini-nuke:cms_system:1.8.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mini-nuke:cms_system:1.8.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0203</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-10-03T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-05-02T10:50:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24101" xml:lang="en">mininuke-membership-change-password(24101)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0173" xml:lang="en">ADV-2006-0173</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421748/100/0/threaded" xml:lang="en">20060113 Advisory: MiniNuke CMS System &lt;= 1.8.2 (membership.asp) remoteuser password change exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22385" xml:lang="en">22385</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/344" xml:lang="en">344</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18439" xml:lang="en">18439</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0439.html" xml:lang="en">20060112 Advisory: MiniNuke CMS System &lt;= 1.8.2 (news.asp) SQL Injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0437.html" xml:lang="en">20060112 Advisory: MiniNuke CMS System &lt;= 1.8.2 (membership.asp) remote user password change exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2006-01/0483.html" xml:lang="en">20060129 [xpl#2] MiniNuke 1.8.2 - change member's passwrod &lt; Perl ></vuln:reference>
    </vuln:references>
    <vuln:summary>membership.asp in Mini-Nuke CMS System 1.8.2 and earlier does not verify the old password when changing a password, which allows remote attackers to change the passwords of other members via a lostpassnew action with a modified x parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0204">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wordcircle:wordcircle:2.17"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordcircle:wordcircle:2.17</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0204</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:34.783-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-17T09:44:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24106" xml:lang="en">wordcircle-index-xss(24106)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0185" xml:lang="en">ADV-2006-0185</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16227" xml:lang="en">16227</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421746/100/0/threaded" xml:lang="en">20060112 [eVuln] Wordcircle Multiple SQL Injection &amp; XSS Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22359" xml:lang="en">22359</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18440" xml:lang="en">18440</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/28/summary.html" xml:lang="en">http://evuln.com/vulns/28/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/345" xml:lang="en">345</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Wordcircle 2.17 allow remote attackers to inject arbitrary web script or HTML via (1) the "Course name" field in index.php when the frm parameter has the value "mine" and (2) possibly certain other fields in unspecified scripts.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0205">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wordcircle:wordcircle:2.17"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordcircle:wordcircle:2.17</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0205</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-06T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-05-02T10:52:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24108" xml:lang="en">wordcircle-login-security-bypass(24108)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24105" xml:lang="en">wordcircle-sql-injection(24105)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0185" xml:lang="en">ADV-2006-0185</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16227" xml:lang="en">16227</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421746/100/0/threaded" xml:lang="en">20060112 [eVuln] Wordcircle Multiple SQL Injection &amp; XSS Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421745/100/0/threaded" xml:lang="en">20060112 [eVuln] Wordcircle Authentication Bypass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22358" xml:lang="en">22358</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/346" xml:lang="en">346</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/345" xml:lang="en">345</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18440" xml:lang="en">18440</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/28/summary.html" xml:lang="en">http://evuln.com/vulns/28/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/27/summary.html" xml:lang="en">http://evuln.com/vulns/27/summary.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in Wordcircle 2.17 allow remote attackers to (1) execute arbitrary SQL commands and bypass authentication via the password field in the login action to index.php (involving v_login.php and s_user.php) and (2) have other unknown impact via certain other fields in unspecified scripts.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0206">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:light_weight_calendar:light_weight_calendar:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:light_weight_calendar:light_weight_calendar:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0206</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:58:38.167-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-17T09:46:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16229" xml:lang="en">16229</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18450" xml:lang="en">18450</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/29/summary.html" xml:lang="en">http://evuln.com/vulns/29/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/29/exploit.html" xml:lang="en">http://evuln.com/vulns/29/exploit.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24110" xml:lang="en">lwc-cal-execute-code(24110)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22376" xml:lang="en">22376</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2006-March/000612.html" xml:lang="en">20060318 Source VERIFY - Light Weight Calendar issue is eval injection</vuln:reference>
    </vuln:references>
    <vuln:summary>Eval injection vulnerability in Light Weight Calendar (LWC) 1.0 (20040909) and earlier allows remote attackers to execute arbitrary PHP code via the date parameter in cal.php, which is included by index.php.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0207">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:5.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0207</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-05-02T11:30:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24094" xml:lang="en">php-session-response-splitting(24094)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16220" xml:lang="en">16220</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200603-22.xml" xml:lang="en">GLSA-200603-22</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1015484" xml:lang="en">1015484</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19355" xml:lang="en">19355</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19179" xml:lang="en">19179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18697" xml:lang="en">18697</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18431" xml:lang="en">18431</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0369" xml:lang="en">ADV-2006-0369</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0177" xml:lang="en">ADV-2006-0177</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntulinux.org/support/documentation/usn/usn-261-1" xml:lang="en">USN-261-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/release_5_1_2.php" xml:lang="en">http://www.php.net/release_5_1_2.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:028" xml:lang="en">MDKSA-2006:028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hardened-php.net/advisory_012006.112.html" xml:lang="en">http://www.hardened-php.net/advisory_012006.112.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1331" xml:lang="en">DSA-1331</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/25945" xml:lang="en">25945</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19012" xml:lang="en">19012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html" xml:lang="en">SUSE-SR:2006:004</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0208">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta_4_patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:5.0.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.10</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta_4_patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.11</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.8</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.9</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0208</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T18:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-13T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-17T09:55:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10064" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10064" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16803" xml:lang="en">16803</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/release_5_1_2.php" xml:lang="en">http://www.php.net/release_5_1_2.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200603-22.xml" xml:lang="en">GLSA-200603-22</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19355" xml:lang="en">19355</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19179" xml:lang="en">19179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18697" xml:lang="en">18697</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18431" xml:lang="en">18431</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=178028" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=178028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/2685" xml:lang="en">ADV-2006-2685</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0369" xml:lang="en">ADV-2006-0369</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0177" xml:lang="en">ADV-2006-0177</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntulinux.org/support/documentation/usn/usn-261-1" xml:lang="en">USN-261-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2006-0501.html" xml:lang="en">RHSA-2006:0501</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/ChangeLog-4.php#4.4.2" xml:lang="en">http://www.php.net/ChangeLog-4.php#4.4.2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:028" xml:lang="en">MDKSA-2006:028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/21564" xml:lang="en">21564</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/21252" xml:lang="en">21252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20951" xml:lang="en">20951</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20222" xml:lang="en">20222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/20210" xml:lang="en">20210</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19832" xml:lang="en">19832</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/19012" xml:lang="en">19012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2006-0549.html" xml:lang="en">RHSA-2006:0549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2006-0276.html" xml:lang="en">RHSA-2006:0276</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html" xml:lang="en">SUSE-SR:2006:004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" xml:lang="en">20060501-01-U</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10064" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10064" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0209">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:tanklogger:tanklogger:2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tanklogger:tanklogger:2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0209</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T20:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:35.250-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-15T20:01:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0153" xml:lang="en">ADV-2006-0153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://evuln.com/vulns/26/summary.html" xml:lang="en">http://evuln.com/vulns/26/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/24080" xml:lang="en">tanklogger-generalfunctions-sql-injection(24080)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/16228" xml:lang="en">16228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/421743/100/0/threaded" xml:lang="en">20060112 [eVuln] TankLogger SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22369" xml:lang="en">22369</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/22368" xml:lang="en">22368</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/341" xml:lang="en">341</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/18441" xml:lang="en">18441</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2006-January/000480.html" xml:lang="en">20060113 Verified TankLogger SQl inject by source inspection</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in general_functions.php in TankLogger 2.4 allows remote attackers to execute arbitrary SQL commands via the (1) livestock_id parameter to showInfo.php and (2) tank_id parameter, possibly to livestock.php.</vuln:summary>
  </entry>
  <entry id="CVE-2006-0210">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:interspire:trackpoint_nx"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:interspire:trackpoint_nx</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2006-0210</vuln:cve-id>
    <vuln:published-datetime>2006-01-13T20:03:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:29:35.347-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2006-01-15T22:25:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2006/0175" xml:lang="en">ADV-2006-0175</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www